logo

WhatsApp Chat Histories Exposed in Unencrypted Storage on macOS and iOS

ID: a38c9de7-158a-5707-a8c8-2b5569d0c230

STIX ID: report--a38c9de7-158a-5707-a8c8-2b5569d0c230

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Divya

...
...

Security researchers found that WhatsApp stores chat histories in plaintext within a shared app group container (group.com.facebook.family) on iOS and macOS, allowing other apps from the same developer ecosystem or an attacker who bypasses OS protections to access messages; this risk is amplified by a disclosed macOS Archive Utility vulnerability (CVE-2026-28910) that can bypass the App Sandbox and enable extraction of protected app containers and backups. Researchers demonstrated backup extraction and a proof-of-concept combining the storage behavior and sandbox bypass, but no large-scale exploitation has been reported; recommended mitigations include enabling encrypted backups, keeping systems updated, using strong device-level encryption and passcodes, and limiting apps from the same developer ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.