WhatsApp Silent Fix of Device Fingerprinting Privacy Issue Assessment: The Good, The (Not So) Bad…
ID: 8539cf65-4673-5284-9ec9-cc4864d9b2c8
STIX ID: report--8539cf65-4673-5284-9ec9-cc4864d9b2c8
Feed Name: Tal Be'ery
Threat Score
Researchers found that WhatsApp's end-to-end encrypted multi-device design leaked per-device encryption metadata that can be used to fingerprint a recipient's operating system and target device-specific exploits; the vendor has silently rolled out a partial fix (Android randomizing a key ID) that reduces but does not eliminate distinguishability, and the report criticizes the lack of CVE issuance and collaborator transparency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
