Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung Galaxy A37 vs Galaxy S25 FE: Expected differences

    November 18, 2025

    What is a VPN and what can you do with one?

    November 18, 2025

    Medieval spear pulled from Polish lake may have belonged to prince or nobleman

    November 18, 2025
    Facebook X (Twitter) Instagram
    Tuesday, November 18
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Gemini 3 Is Here—and Google Says It Will Make Search Smarter

      November 18, 2025

      14 Best Housewarming Gifts We Can't Stop Using (2025): Coasters, Blenders, Sheets

      November 18, 2025

      A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

      November 18, 2025

      14 Best Fitness Trackers (2025), Tested and Reviewed

      November 18, 2025

      The Best Home Cocktail Machines—and Whether You Need One

      November 18, 2025
    • Science & Education

      Medieval spear pulled from Polish lake may have belonged to prince or nobleman

      November 18, 2025

      Violent queen ant coup staged by parasitic ants

      November 18, 2025

      Can one big meal really make you gain weight?

      November 18, 2025

      4,000-year-old silver goblet tells a tale of chaos and order

      November 18, 2025

      The Sony wireless headphones and speakers you wanted all year are up to 40% off during Amazon’s Early Black Friday sale

      November 18, 2025
    • Mobile Phones

      Samsung Galaxy A37 vs Galaxy S25 FE: Expected differences

      November 18, 2025

      Google Play just announced its best apps and games for 2025

      November 18, 2025

      The iPhone 17 dominated this market in October – and you’ll be surprised which one

      November 18, 2025

      Rare JBL Boombox 3 deal at Amazon saves you 30% ahead of Black Friday Week

      November 18, 2025

      The Galaxy Tab S6 Lite (2024) is 52% off in an unheard-of early Black Friday deal

      November 18, 2025
    • Gadgets

      What is a VPN and what can you do with one?

      November 18, 2025

      Xbox Game Pass Ultimate now includes a Fortnite Crew subscription

      November 18, 2025

      Mastodon’s founder is no longer its CEO

      November 18, 2025

      Interplay co-founder Rebecca Heineman dies

      November 18, 2025

      Cloudflare hit by outage causing ‘widespread’ errors

      November 18, 2025
    • Gaming

      SanDisk 2TB SSD Falls to New All-Time Low, Amazon Wants All Stock Gone for Black Friday

      November 18, 2025

      Asus ROG Strix G16 (Ryzen 9, RTX 5070, 1TB) Drops to Peanuts, Amazon Offloads 2025 Model Stock

      November 18, 2025

      The Best Sims 4 Expansion Packs and DLC

      November 18, 2025

      SpongeBob SquarePants Claw Machine From Arcade1Up Now Available To Preorder

      November 18, 2025

      New Surprise Xbox Event Will Reveal Game Pass News And More

      November 18, 2025
    • Cars

      Top 10 Most Common Car Repairs and How to Avoid Them?

      November 18, 2025

      A Safety Guide for Ride Share Drivers

      November 17, 2025

      Top 10 Cars for Sale

      November 17, 2025

      The exquisite and amazing 1935 Auburn 851 Speedster

      November 17, 2025

      Why buying a damaged car from the USA can be risky- even when the price looks great

      November 15, 2025
    • PC Accessories

      Why Wait For A Steam Machine When You Can Just Use A Steam Machine

      November 17, 2025

      Podcast #844 – AMD Ryzen news, RTX SUPER rumor, Sapphire B850 motherboard, HDD Shortages, Valve Steam Machine + MORE!

      November 16, 2025

      Upgrade Your Desk’s Audio With Creative’s Pebble Nova Premium 2.0 Speakers

      November 14, 2025

      The Philips 34B2U6603CH Ultrawide Thunderbolt 4 Display

      November 14, 2025

      Running An ASUS DSL Router? Three Models Need A Patch ASAP

      November 14, 2025
    ToolcomeToolcome
    Home»Technology & Startups»A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
    Technology & Startups

    A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

    November 18, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    WhatsApp’s mass adoption stems in part from how easy it is to find a new contact on the messaging platform: Add someone’s phone number, and WhatsApp instantly shows whether they’re on the service, and often their profile picture and name, too.

    Repeat that same trick a few billion times with every possible phone number, it turns out, and the same feature can also serve as a convenient way to obtain the cell number of virtually every WhatsApp user on earth—along with, in many cases, profile photos and text that identifies each of those users. The result is a sprawling exposure of personal information for a significant fraction of the world population.

    One group of Austrian researchers have now shown that they were able to use that simple method of checking every possible number in WhatsApp’s contact discovery to extract 3.5 billion users’ phone numbers from the messaging service. For about 57 percent of those users, they also found that they could access their profile photos, and for another 29 percent, the text on their profiles. Despite a previous warning about WhatsApp’s exposure of this data from a different researcher in 2017, they say, the service’s parent company, Meta, still failed to limit the speed or number of contact discovery requests the researchers could make by interacting with WhatsApp’s browser-based app, allowing them to check roughly a hundred million numbers an hour.

    The result would be “the largest data leak in history, had it not been collated as part of a responsibly conducted research study,” as the researchers describe it in a paper documenting their findings.

    “To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented,” says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.

    The researchers say they warned Meta about their findings in April and deleted their copy of the 3.5 billion phone numbers. By October, the company had fixed the enumeration problem by enacting a stricter “rate-limiting” measure that prevents the mass-scale contact discovery method the researchers used. But until then, the data exposure could have also been exploited by anyone else using the same scraping technique, adds Max Günther, another researcher from the university who cowrote the paper. “If this could be retrieved by us super easily, others could have also done the same,” he says.

    In a statement to WIRED, Meta thanked the researchers, who reported their discovery through Meta’s “bug bounty” system, and described the exposed data as “basic publicly available information,” since profile photos and text weren’t exposed for users who opted to make it private. “We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defenses,” writes Nitin Gupta, vice president of engineering at WhatsApp. Gupta adds, “We have found no evidence of malicious actors abusing this vector. As a reminder, user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption, and no non-public data was accessible to the researchers.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    Gemini 3 Is Here—and Google Says It Will Make Search Smarter

    November 18, 2025

    14 Best Housewarming Gifts We Can't Stop Using (2025): Coasters, Blenders, Sheets

    November 18, 2025

    14 Best Fitness Trackers (2025), Tested and Reviewed

    November 18, 2025

    The Best Home Cocktail Machines—and Whether You Need One

    November 18, 2025

    Social Security Data Is Openly Being Shared With DHS to Target Immigrants

    November 18, 2025

    Benoit Blanc takes on a “perfectly impossible crime” in Wake Up Dead Man trailer

    November 18, 2025
    Leave A Reply Cancel Reply

    Top Posts

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202528 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202524 Views

    World’s biggest spiderweb discovered inside ‘Sulfur Cave’ with 111,000 arachnids living in pitch black

    November 4, 202521 Views
    Don't Miss

    Samsung Galaxy A37 vs Galaxy S25 FE: Expected differences

    November 18, 2025

    Samsung’s upcoming Galaxy A37 is shaping up to be a rather small upgrade to the…

    What is a VPN and what can you do with one?

    November 18, 2025

    Medieval spear pulled from Polish lake may have belonged to prince or nobleman

    November 18, 2025

    Gemini 3 Is Here—and Google Says It Will Make Search Smarter

    November 18, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    These Galaxy phones were attacked by spyware for nearly a year before a patch was released

    November 10, 202528 Views

    Rumored Verizon decision will let down both customers and employees

    November 7, 202524 Views

    World’s biggest spiderweb discovered inside ‘Sulfur Cave’ with 111,000 arachnids living in pitch black

    November 4, 202521 Views
    Our Picks

    Samsung Galaxy A37 vs Galaxy S25 FE: Expected differences

    November 18, 2025

    What is a VPN and what can you do with one?

    November 18, 2025

    Medieval spear pulled from Polish lake may have belonged to prince or nobleman

    November 18, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2025 Tolcome. Designed by Aim Digi Ltd.

    Type above and press Enter to search. Press Esc to cancel.