Teknologji 2025-11-23 18:45:00 Nga VNA

WhatsApp exposed 3.5 billion accounts: researchers discover massive privacy vulnerability

Ndaje në Whatsapp
WhatsApp exposed 3.5 billion accounts: researchers discover massive privacy

A group of cybersecurity researchers from the University of Vienna and SBA Research have discovered a large-scale vulnerability in WhatsApp's contact search mechanism, which allowed the identification of 3.5 billion active accounts worldwide. The findings were immediately reported to Meta, which has taken measures to mitigate the problem, while the pre-publication of the study is now online and the results will be presented in 2026 at the prestigious NDSS conference.

How was the vulnerability discovered?

WhatsApp uses a user's address book to identify other contacts who use the app, based on their phone number alone. The researchers found that the same logic could be used to send more than 100 million requests per hour, verifying the existence of accounts in 245 countries.

"A system shouldn't have to respond to so many requests from a single source. That's what allowed us to map user data globally," explains Gabriel Gegenhuber, the study's lead author.

Essentially, WhatsApp's servers responded to verification requests in an unlimited manner, creating an opportunity for any actor – with sufficient technical capacity – to build a global inventory of users.

What information was revealed?

The accessible data did not include message content. It was the same data that is publicly visible to anyone who knows someone's number:
• phone number
• public keys
• timestamps
• photo and "About" status, if public.

But this minimal amount of data proved sufficient to extract other information:
• operating system (Android or iOS),
• age of the account,
• number of connected devices.

According to researchers, this metadata also shows how vulnerable users' privacy can be when information is analyzed en masse.

Other alarming findings

The study identified important global trends and phenomena:
• Millions of active WhatsApp users were discovered in countries where the platform is banned, such as China, Iran, and Myanmar.
• 81% of global users are on Android, while 19% are on iOS.
• Regional differences in privacy behavior were noted, such as the use of a profile photo or “About” message.
• In some cases, reuse of cryptographic keys was found, a clear signal of the use of unofficial or pirated WhatsApp clients.
• Nearly half of the numbers leaked in the Facebook scandal in 2021 continue to be active on WhatsApp, increasing the risks of scams and unwanted calls.

WhatsApp: messages were secure

Meta emphasizes that the content of the messages, thanks to end-to-end encryption, has always been protected. The vulnerability only affected metadata and public data.

“We have not found any evidence that malicious actors have exploited this technique,” ​​said Nitin Gupta, vice president of engineering at WhatsApp.
He confirmed that Meta has implemented new anti-scraping measures, such as limiting requests and reducing the visibility of public profile information.

All data collected by researchers was deleted before publication.

Why is this study important?

Researchers from Vienna have been tracking the security of instant messaging platforms for years. Previously, they discovered:
• ways to monitor users' online behavior through "silent delivery receipts",
• vulnerabilities in WhatsApp's key distribution ("prekeys").

The new study, "Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy," marks the most important steps in understanding the risks that come from the way messaging services are designed and operate.

“Even the largest and most trusted systems have vulnerabilities that need to be continuously addressed,” says Gegenhuber.

The researchers emphasize that transparency, independent research, and collaboration with industry are essential for protecting the privacy of billions of users who rely on communication platforms every day.

Video

Rama është modest. Ai është “bujari” i vërtetë. Se i ka dhënë tokën e pronarëve Arbër Hajdarit për 1 euro

Gjatë vizitës së tij në Pekin, presidenti i Francës, Emmanuel Macron, u prit me entuziazëm nga qytetarët kinezë. Një moment që tërhoqi vëmendjen e mediave dhe të publikut ishte kur Macron vrapoi për t’i përshëndetur ata personalisht, duke treguar afërsinë dhe respektin ndaj njerëzve që e pritën. Ky episod simbolik thekson lidhjet gjithnjë e më të forta mes Francës dhe Kinës, si dhe përpjekjet e të dyja vendeve për të thelluar bashkëpunimin ekonomik dhe politik.

Ceremonia e shortit të Kampionatit Botëror përfundoi me një moment të pazakontë, ku presidenti amerikan Donald Trump u pa duke vallëzuar këngën ikonike YMCA, duke tërhequr vëmendjen e mediave dhe të pjesëmarrësve.

Një aligator gjigant, i gjatë rreth 4.3 metra (14-foot) dhe me peshë rreth 272 kg (600 paund), shkaktoi bllokim të trafikut në Florida, duke tërhequr vëmendjen e kalimtarëve dhe drejtuesve të automjeteve. Një kapës i specializuar për kafshë të egra, së bashku me tetë zyrtarë policorë, ndërhynë për të larguar aligatorin nga rruga dhe për të siguruar kalimin e automjeteve në mënyrë të sigurt.

Doni të informoheni të parët për lajme ekskluzive?

Bashkohuni me grupin tonë privat.

opinion

Opinionet e shprehura i përkasin autorëve dhe nuk përfaqësojnë qendrimin e redaksisë.

Forgotten Stories

More news