A massive security flaw in WhatsApp exposed the phone number of nearly every user on the planet, despite parent company Meta having been notified of the vulnerability as early as 2017.
See also: WhatsApp: Abuse of screen sharing to steal data

Security researchers managed to use what they described as a “simple” exploit to extract a total of 3.5 billion phone numbers from the messaging service. The researchers say that if the same exploit had been used by malicious actors, the result would have been “the largest data breach in history.”
The most serious aspect of the privacy failure is that a different security researcher had alerted Meta to the problem more than eight years ago, and in all that time, the company failed to implement the extremely simple safeguard needed to fix it.
WhatsApp's mass adoption is partly due to how easy it is to find a new contact on the messaging platform: Add someone's phone number and WhatsApp immediately shows whether they're on the service and often their profile photo and name as well.
See also: WhatsApp: Third-party chat integration in Europe

Repeat this trick a few billion times with every possible phone number, and the same feature can also serve as a convenient way to get the mobile number of almost every WhatsApp user on earth—along with, in many cases, profile photos and text identifying each of those users.
A security researcher in 2017 found that the company provides no limit on the number of phone number checks you can perform, allowing for this type of attack. Incredibly, eight years later, a team of Austrian researchers from the University of Vienna managed to exploit the exact same loophole to obtain the phone number of almost every WhatsApp user. It took them just half an hour to record the first 30 million US phone numbers, and after that, they just kept going.
"To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever recorded," says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.
See also: 'Maverick' malware targets bank customers in Brazil via WhatsApp

The researchers acted responsibly by deleting the phone number database and notifying Meta. It took the company about six more months to implement a rate-limiting measure to prevent the feature from being exploited on this scale. WhatsApp claims it was already working on it and says it has found no evidence of malicious actors exploiting the loophole.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
