By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Gadget > A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
Gadget

A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

News Room
Last updated: 2025/11/18 at 10:15 AM
News Room Published 18 November 2025
Share
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
SHARE

WhatsApp’s mass adoption stems in part from how easy it is to find a new contact on the messaging platform: Add someone’s phone number, and WhatsApp instantly shows whether they’re on the service, and often their profile picture and name, too.

Repeat that same trick a few billion times with every possible phone number, it turns out, and the same feature can also serve as a convenient way to obtain the cell number of virtually every WhatsApp user on earth—along with, in many cases, profile photos and text that identifies each of those users. The result is a sprawling exposure of personal information for a significant fraction of the world population.

One group of Austrian researchers have now shown that they were able to use that simple method of checking every possible number in WhatsApp’s contact discovery to extract 3.5 billion users’ phone numbers from the messaging service. For about 57 percent of those users, they also found that they could access their profile photos, and for another 29 percent, the text on their profiles. Despite a previous warning about WhatsApp’s exposure of this data from a different researcher in 2017, they say, the service’s parent company, Meta, still failed to limit the speed or number of contact discovery requests the researchers could make by interacting with WhatsApp’s browser-based app, allowing them to check roughly a hundred million numbers an hour.

The result would be “the largest data leak in history, had it not been collated as part of a responsibly conducted research study,” as the researchers describe it in a paper documenting their findings.

“To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented,” says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.

The researchers say they warned Meta about their findings in April and deleted their copy of the 3.5 billion phone numbers. By October, the company had fixed the enumeration problem by enacting a stricter “rate-limiting” measure that prevents the mass-scale contact discovery method the researchers used. But until then, the data exposure could have also been exploited by anyone else using the same scraping technique, adds Max Günther, another researcher from the university who cowrote the paper. “If this could be retrieved by us super easily, others could have also done the same,” he says.

In a statement to WIRED, Meta thanked the researchers, who reported their discovery through Meta’s “bug bounty” system, and described the exposed data as “basic publicly available information,” since profile photos and text weren’t exposed for users who opted to make it private. “We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defenses,” writes Nitin Gupta, vice president of engineering at WhatsApp. Gupta adds, “We have found no evidence of malicious actors abusing this vector. As a reminder, user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption, and no non-public data was accessible to the researchers.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Is your department the most polluting in France? Is your department the most polluting in France?
Next Article TikTok goes dark in the United States TikTok goes dark in the United States
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Influencer Marketing in Ecommerce​: Ultimate Guide in 2025
Computing
AI-Generated Code Creates New Wave of Technical Debt, Report Finds
AI-Generated Code Creates New Wave of Technical Debt, Report Finds
News
Do you really need to buy a new TV? Seven simple ways to upgrade your setup (some are even free)
Do you really need to buy a new TV? Seven simple ways to upgrade your setup (some are even free)
Software
Apple’s custom Wi-Fi chip gives the iPhone 17 a notable boost, according to speed tests
Apple’s custom Wi-Fi chip gives the iPhone 17 a notable boost, according to speed tests
News

You Might also Like

Govee X JBL Table Lamp 2 Pro Review: The perfect party starter
Gadget

Govee X JBL Table Lamp 2 Pro Review: The perfect party starter

15 Min Read
I’m a Heavy Sleeper, so I Tried 6 Extreme Alarm Clocks That Shock and Roll
Gadget

I’m a Heavy Sleeper, so I Tried 6 Extreme Alarm Clocks That Shock and Roll

4 Min Read
Score 60% off the Blink Mini 2 security camera this Black Friday
Gadget

Score 60% off the Blink Mini 2 security camera this Black Friday

4 Min Read
Omega launches the 4th gen of the Planet Ocean with a complete redesign and seven new models
Gadget

Omega launches the 4th gen of the Planet Ocean with a complete redesign and seven new models

0 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?