logo

WhatsApp Silent Fix of Device Fingerprinting Privacy Issue Assessment: The Good, The (Not So) Bad…

ID: 8539cf65-4673-5284-9ec9-cc4864d9b2c8

STIX ID: report--8539cf65-4673-5284-9ec9-cc4864d9b2c8

Feed Name: Tal Be'ery

Threat Score
60/100

Date Published: 2026-01-05

Date Updated: 2026-04-19

Author: Tal Be'ery

...
...

Researchers found that WhatsApp's end-to-end encrypted multi-device design leaked per-device encryption metadata that can be used to fingerprint a recipient's operating system and target device-specific exploits; the vendor has silently rolled out a partial fix (Android randomizing a key ID) that reduces but does not eliminate distinguishability, and the report criticizes the lack of CVE issuance and collaborator transparency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.