logo

WhatsApp View Once Privacy Issue Initial Fix Assessment: The Good, the Bad and The Ugly

ID: 2cbcd7e1-54c7-55fa-9644-9a3dbd67a013

STIX ID: report--2cbcd7e1-54c7-55fa-9644-9a3dbd67a013

Feed Name: Tal Be'ery

Threat Score
65/100

Date Published: 2024-09-16

Date Updated: 2026-04-19

Author: Tal Be'ery

...
...

**TL;DR:** Researchers disclosed a trivial bypass of WhatsApp’s "View Once" media privacy feature—public browser extensions (≈10K users) and simple client/database edits can make View Once media viewable; WhatsApp’s Web app update redacts stored data and broke many extensions but does not fully prevent upstream tampering, so attackers can still evade the mitigation. The report urges a robust fix (sending restricted content only to allowed devices) and criticizes Meta’s lack of bug-bounty communication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.