Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information
ID: 48882a49-df98-5aba-b265-37dc47bb4e0a
STIX ID: report--48882a49-df98-5aba-b265-37dc47bb4e0a
Feed Name: cybersecurityNews.com
Security researchers disclosed a privacy vulnerability called “Careless Whisper” that lets attackers abuse silent delivery receipts and RTT timing in WhatsApp and Signal to infer device state, app usage, and user activity (including battery and network changes) without alerts or prior contact; the issue affects billions of users, enables high-frequency probing (causing data/battery drain), and remains without a full patch, with researchers recommending contact-restricted receipts, RTT noise, message ID validation, and server rate limits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
