{"id":8556,"date":"2025-11-19T10:03:30","date_gmt":"2025-11-19T10:03:30","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/19\/whatsapp-vulnerability-exposes-3-5-billion-users-phone-numbers\/"},"modified":"2025-11-19T10:03:30","modified_gmt":"2025-11-19T10:03:30","slug":"whatsapp-vulnerability-exposes-3-5-billion-users-phone-numbers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/19\/whatsapp-vulnerability-exposes-3-5-billion-users-phone-numbers\/","title":{"rendered":"WhatsApp Vulnerability Exposes 3.5 Billion Users\u2019 Phone Numbers"},"content":{"rendered":"<p>    WhatsApp Vulnerability Exposes 3.5 Billion Users\u2019 Phone Numbers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical security flaw in <a href=\"https:\/\/cybersecuritynews.com\/tag\/whatsapp\/\" target=\"_blank\" rel=\"noreferrer noopener\">WhatsApp<\/a> has allowed researchers to expose the phone numbers of 3.5 billion users, marking one of the most significant data leaks ever documented.<\/p>\n<p>This vulnerability, rooted in the app\u2019s contact discovery feature, persisted despite warnings to Meta dating back to 2017, raising serious concerns about user privacy on the world\u2019s most popular messaging platform.\u200b<\/p>\n<p>The exploit relies on WhatsApp\u2019s built-in mechanism for finding contacts, which reveals whether a user is on the service and public details like profile pictures and status texts when a phone number is entered.<\/p>\n<p>Security researchers from the University of Vienna demonstrated the flaw by systematically querying billions of potential numbers, confirming active accounts at a rate of over 100 million per hour without any restrictions from WhatsApp.<\/p>\n<p>Their study, conducted between December 2024 and April 2025, generated a comprehensive dataset using a tool called libphonegen to create realistic phone numbers across 245 countries.<\/p>\n<p>By leveraging WhatsApp\u2019s XMPP protocol through a modified open-source client, the team accessed not only phone numbers but also encryption keys, timestamps, and public profile information for 56.7% of accounts.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-whatsapp-vulnerability-exposes-3-5-billion-users\"><strong>WhatsApp Vulnerability Exposes 3.5 Billion Users <\/strong><\/h2>\n<p>WhatsApp\u2019s contact discovery tool, designed for convenience, lacks robust rate-limiting, enabling automated scraping on a massive scale. The researchers used just five authenticated accounts on a single university server to probe 63 billion potential numbers, identifying 3.5 billion active ones in under six months.<\/p>\n<p>For 29.3% of users, \u201cabout\u201d texts revealed sensitive details such as political views, religious affiliations, or links to other social media profiles.<\/p>\n<p>Alarmingly, the study uncovered 2.9 million cases of public key reuse, including identity and prekeys, which could undermine end-to-end encryption if exploited by malicious actors using unofficial clients.<\/p>\n<p>One extreme example involved 20 U.S. numbers sharing a key of all zeros, suggesting potential fraud or broken implementations.\u200b<\/p>\n<p>This vulnerability echoes earlier warnings; a researcher flagged the issue in 2017, yet Meta delayed fixes for eight years. The exposed data overlaps significantly with prior breaches, like the 2021 Facebook leak of 500 million numbers, where nearly half remained active on WhatsApp, heightening risks for scams and targeted attacks.<\/p>\n<p>Users in countries banning WhatsApp, such as China, Iran, and North Korea, face amplified dangers, including state surveillance or persecution.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-meta-s-response-and-ongoing-risks\"><strong>Meta\u2019s Response and Ongoing Risks<\/strong><\/h2>\n<p>Meta acknowledged the findings through its bug bounty program in April 2025 and implemented stricter rate limits in October 2025, claiming the data was already public and messages stayed encrypted.<\/p>\n<p>WhatsApp VP of Engineering Nitin Gupta stated the company was developing anti-scraping measures, and the research helped stress-test them, with no evidence of malicious exploitation found.<\/p>\n<p>The researchers responsibly deleted their dataset and <a href=\"https:\/\/github.com\/sbaresearch\/whatsapp-census\/blob\/main\/Hey_there_You_are_using_WhatsApp.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">emphasized<\/a> that private profiles limited exposure, but they criticized Meta for not encountering defenses during the probe.\u200b<\/p>\n<p>Despite the patch, experts warn of lingering threats. Business accounts, comprising 9% of those scraped, often unwittingly expose more data via WhatsApp Business features.<\/p>\n<p>The flaw highlights broader issues in enumeration attacks, where convenience features become privacy pitfalls, potentially fueling <a href=\"https:\/\/cybersecuritynews.com\/phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a>, SIM-swapping, or doxxing campaigns. Cybersecurity analysts urge users to set profiles to private, avoid sharing personal details in statuses, and monitor for suspicious activity, especially post-leak.\u200b<\/p>\n<p>This incident underscores the challenges of securing platforms with billions of users, where even \u201cpublic\u201d data aggregation creates a shadow profile ecosystem.<\/p>\n<p>As WhatsApp dominates messaging in regions like West Africa, where 80% of profiles were public, the risks of <a href=\"https:\/\/cybersecuritynews.com\/identity-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">identity theft<\/a> and cyberattacks escalate.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Rank<\/th>\n<th>Country<\/th>\n<th># Accounts<\/th>\n<th>Global Share<\/th>\n<th>Android (%)<\/th>\n<th>iOS (%)<\/th>\n<th>Picture (%)<\/th>\n<th>About Text (%)<\/th>\n<th>Business (%)<\/th>\n<th>Companions (%)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1<\/td>\n<td>India<\/td>\n<td>749,075,246<\/td>\n<td>21.67%<\/td>\n<td>95<\/td>\n<td>5<\/td>\n<td>62.2<\/td>\n<td>29.5<\/td>\n<td>9.8<\/td>\n<td>6.2<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>Indonesia<\/td>\n<td>235,245,077<\/td>\n<td>6.81%<\/td>\n<td>92<\/td>\n<td>8<\/td>\n<td>49.1<\/td>\n<td>27.5<\/td>\n<td>10.7<\/td>\n<td>9.3<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>Brazil<\/td>\n<td>206,949,224<\/td>\n<td>5.99%<\/td>\n<td>81<\/td>\n<td>19<\/td>\n<td>61.1<\/td>\n<td>41.5<\/td>\n<td>10.3<\/td>\n<td>15.5<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>United States<\/td>\n<td>137,859,284<\/td>\n<td>3.99%<\/td>\n<td>33<\/td>\n<td>67<\/td>\n<td>44.0<\/td>\n<td>32.8<\/td>\n<td>2.4<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>Russia<\/td>\n<td>132,855,022<\/td>\n<td>3.84%<\/td>\n<td>76<\/td>\n<td>24<\/td>\n<td>61.7<\/td>\n<td>33.5<\/td>\n<td>3.6<\/td>\n<td>9.4<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>Mexico<\/td>\n<td>128,324,166<\/td>\n<td>3.71%<\/td>\n<td>82<\/td>\n<td>18<\/td>\n<td>46.1<\/td>\n<td>23.3<\/td>\n<td>4.1<\/td>\n<td>11.7<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>Pakistan<\/td>\n<td>98,277,665<\/td>\n<td>2.84%<\/td>\n<td>95<\/td>\n<td>5<\/td>\n<td>58.5<\/td>\n<td>20.0<\/td>\n<td>21.7<\/td>\n<td>5.4<\/td>\n<\/tr>\n<tr>\n<td>8<\/td>\n<td>Germany<\/td>\n<td>74,565,425<\/td>\n<td>2.16%<\/td>\n<td>58<\/td>\n<td>42<\/td>\n<td>51.0<\/td>\n<td>35.4<\/td>\n<td>2.2<\/td>\n<td>13.4<\/td>\n<\/tr>\n<tr>\n<td>9<\/td>\n<td>T\u00fcrkiye<\/td>\n<td>72,131,903<\/td>\n<td>2.09%<\/td>\n<td>73<\/td>\n<td>27<\/td>\n<td>48.0<\/td>\n<td>33.4<\/td>\n<td>3.0<\/td>\n<td>12.0<\/td>\n<\/tr>\n<tr>\n<td>10<\/td>\n<td>Egypt<\/td>\n<td>69,317,806<\/td>\n<td>2.01%<\/td>\n<td>90<\/td>\n<td>10<\/td>\n<td>53.2<\/td>\n<td>25.1<\/td>\n<td>11.3<\/td>\n<td>6.1<\/td>\n<\/tr>\n<tr>\n<td>11\u2013245<\/td>\n<td>Others<\/td>\n<td>1,552,021,571<\/td>\n<td>44.90%<\/td>\n<td>77<\/td>\n<td>23<\/td>\n<td>56.9<\/td>\n<td>27.9<\/td>\n<td>9.3<\/td>\n<td>9.0<\/td>\n<\/tr>\n<tr>\n<td>Global<\/td>\n<td>(245 countries)<\/td>\n<td>3,456,622,389<\/td>\n<td>100.00%<\/td>\n<td>81<\/td>\n<td>19<\/td>\n<td>56.7<\/td>\n<td>29.3<\/td>\n<td>9.0<\/td>\n<td>8.8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Regulators may scrutinize Meta further following <a href=\"https:\/\/cybersecuritynews.com\/gdpr-compliance-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR fines<\/a> for past lapses, pushing for proactive defenses such as advanced CAPTCHA or behavioral analysis.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/whatsapp-vulnerability-exposes-3-5-billion-users\/\">WhatsApp Vulnerability Exposes 3.5 Billion Users\u2019 Phone Numbers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/whatsapp-vulnerability-exposes-3-5-billion-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WhatsApp Vulnerability Exposes 3.5 Billion Users\u2019 Phone Numbers A critical security flaw in WhatsApp has allowed researchers to expose the phone numbers of 3.5 billion users, marking one of the most significant data leaks ever documented. This vulnerability, rooted in the app\u2019s contact discovery feature, persisted despite warnings to Meta dating back to 2017, raising [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1738],"tags":[130],"class_list":["post-8556","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-leak","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8556"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8556"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8556\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}