logo

WhatsApp closes loophole that let researchers collect data on 3.5B accounts

ID: befd8f5c-0754-58de-a252-a89eedd12bbb

STIX ID: report--befd8f5c-0754-58de-a252-a89eedd12bbb

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2025-11-25

Date Updated: 2026-04-28

...
...

Researchers found that WhatsApp's contact-discovery API could be abused to enumerate and confirm over 3.5 billion phone numbers (at a rate exceeding 100 million lookups per hour and ~7,000 queries/sec from one IP), allowing collection of publicly visible profile photos, 'about' text, and metadata; the flaw is due to insufficient rate-limiting, poses serious privacy risks (including potential facial-recognition mapping and exposure of sensitive information), and prompted Meta to implement stricter anti-scraping measures after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.