logo

Once and Forever: WhatsApp’s View Once Functionality is Broken

ID: c26547b4-36bc-54cd-9e10-633a8250e894

STIX ID: report--c26547b4-36bc-54cd-9e10-633a8250e894

Feed Name: Tal Be'ery

Threat Score
75/100

Date Published: 2024-09-09

Date Updated: 2026-04-19

Author: Tal Be'ery

...
...

This report demonstrates that WhatsApp’s “View once” ephemeral-media feature is implemented insecurely: media are uploaded as normal encrypted blobs and sent to all linked devices with a client-side flag that can be toggled or ignored, allowing attackers or modified clients to obtain exact digital copies of supposedly ephemeral content. The researchers built proofs-of-concept (an unofficial client and referenced browser extensions), found evidence of in-the-wild exploitation, responsibly disclosed to Meta, and recommend DRM or restricting delivery to primary devices as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.