|
Navigation
Search
|
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
Tuesday November 18, 2025. 03:59 PM , from Slashdot
The team warned Meta in April and deleted their data. The company implemented stricter rate-limiting by October to prevent such mass enumeration. Meta called the exposed information 'basic publicly available information' and said it found no evidence of malicious exploitation. The vulnerability had been identified before. In 2017, Dutch researcher Loran Kloeze published a blog post detailing the same enumeration technique. Meta responded then that WhatsApp's privacy settings were functioning as designed and denied him a bug bounty reward. The researchers collected 137 million U.S. phone numbers. In India, they found nearly 750 million numbers. They also discovered 2.3 million Chinese numbers and 1.6 million Myanmar numbers, despite WhatsApp being banned in both countries. The researchers analyzed the cryptographic keys and found some accounts used duplicate keys. They speculate this resulted from unauthorized WhatsApp clients rather than a platform flaw. Read more of this story at Slashdot.
https://yro.slashdot.org/story/25/11/18/1459209/a-simple-whatsapp-security-flaw-exposed-35-billion-p...
Related News |
25 sources
Current Date
Nov, Tue 18 - 18:00 CET
|







