Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    New Mexico goes to trial to accuse Meta of facilitating child predators

    New Mexico goes to trial to accuse Meta of facilitating child predators

    February 9, 2026
    Siemens CEO Roland Busch’s mission to automate everything

    Siemens CEO Roland Busch’s mission to automate everything

    February 9, 2026
    FCC accused of withholding DOGE information ‘in bad faith’

    FCC accused of withholding DOGE information ‘in bad faith’

    February 9, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
    Security

    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    News RoomBy News RoomNovember 20, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    WhatsApp’s mass adoption stems in part from how easy it is to find a new contact on the messaging platform: Add someone’s phone number, and WhatsApp instantly shows whether they’re on the service, and often their profile picture and name, too.

    Repeat that same trick a few billion times with every possible phone number, it turns out, and the same feature can also serve as a convenient way to obtain the cell number of virtually every WhatsApp user on earth—along with, in many cases, profile photos and text that identifies each of those users. The result is a sprawling exposure of personal information for a significant fraction of the world population.

    One group of Austrian researchers have now shown that they were able to use that simple method of checking every possible number in WhatsApp’s contact discovery to extract 3.5 billion users’ phone numbers from the messaging service. For about 57 percent of those users, they also found that they could access their profile photos, and for another 29 percent, the text on their profiles. Despite a previous warning about WhatsApp’s exposure of this data from a different researcher in 2017, they say, the service’s parent company, Meta, still failed to limit the speed or number of contact discovery requests the researchers could make by interacting with WhatsApp’s browser-based app, allowing them to check roughly a hundred million numbers an hour.

    The result would be “the largest data leak in history, had it not been collated as part of a responsibly conducted research study,” as the researchers describe it in a paper documenting their findings.

    “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented,” says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.

    The researchers say they warned Meta about their findings in April and deleted their copy of the 3.5 billion phone numbers. By October, the company had fixed the enumeration problem by enacting a stricter “rate-limiting” measure that prevents the mass-scale contact discovery method the researchers used. But until then, the data exposure could have also been exploited by anyone else using the same scraping technique, adds Max Günther, another researcher from the university who cowrote the paper. “If this could be retrieved by us super easily, others could have also done the same,” he says.

    In a statement to WIRED, Meta thanked the researchers, who reported their discovery through Meta’s “bug bounty” system, and described the exposed data as “basic publicly available information,” since profile photos and text weren’t exposed for users who opted to make it private. “We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defenses,” writes Nitin Gupta, vice president of engineering at WhatsApp. Gupta adds, “We have found no evidence of malicious actors abusing this vector. As a reminder, user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption, and no non-public data was accessible to the researchers.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleIn Alex Karp’s World, Palantir Is the Underdog
    Next Article Microsoft’s AI-powered copy and paste can now use on-device AI

    Related Posts

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    December 6, 2025
    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    December 5, 2025
    Your Data Might Determine How Much You Pay for Eggs

    Your Data Might Determine How Much You Pay for Eggs

    December 4, 2025
    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    December 4, 2025
    This Hacker Conference Installed a Literal Antivirus Monitoring System

    This Hacker Conference Installed a Literal Antivirus Monitoring System

    December 4, 2025
    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    December 4, 2025
    Our Picks
    Siemens CEO Roland Busch’s mission to automate everything

    Siemens CEO Roland Busch’s mission to automate everything

    February 9, 2026
    FCC accused of withholding DOGE information ‘in bad faith’

    FCC accused of withholding DOGE information ‘in bad faith’

    February 9, 2026
    MrBeast just bought a banking app

    MrBeast just bought a banking app

    February 9, 2026
    ChatGPT’s cheapest options now show you ads

    ChatGPT’s cheapest options now show you ads

    February 9, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    The Verge’s 2026 Valentine’s Day gift guide (for her) News

    The Verge’s 2026 Valentine’s Day gift guide (for her)

    By News RoomFebruary 9, 2026

    Valentine’s Day often comes with more pressure than it needs to. At heart, though, February…

    Apple is killing the old HomeKit tomorrow

    Apple is killing the old HomeKit tomorrow

    February 9, 2026
    Linux 6.19 arrives with a teaser for Linux 7.0

    Linux 6.19 arrives with a teaser for Linux 7.0

    February 9, 2026
    Ferrari’s first EV will have an interior designed by Jony Ive

    Ferrari’s first EV will have an interior designed by Jony Ive

    February 9, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.