WhatsApp and Meta claim that the app uses end -to-end encryption, meaning that no one but the sender and recipient can access the contents of a conversation. However, a lawsuit against the company claims that this is not true and that anyone within Meta can gain full access to all messages sent or received by any WhatsApp user.

WhatsApp founders Jan Koum and Brian Actonbuilt the messaging app around end-to-end encryption (E2EE), with governments and law enforcement agencies expressing concerns at the time about the inability to access content.
See also: WhatsApp introduces new security feature for some users
WhatsApp end-to-end encryption
E2EE means that only the participants in the conversation have access to the keys needed to decrypt the content of the messages. While these messages are sent through WhatsApp's servers, they are sent in encrypted form, and there should be no way for the company to decrypt the data.
However, a class action lawsuit claims that this is a lie and that WhatsApp does not actually use E2EE:
“Meta and WhatsApp’s claim that they do not have access to the content of WhatsApp users’ communications is false. As whistleblowers have explained, WhatsApp and Meta store and have unrestricted access to encrypted communications WhatsApp. The process for Meta employees to gain this access is quite simple. An employee only needs to send a “task” (i.e., a request through Meta’s internal system) to a Meta engineer explaining that they need access to WhatsApp messages for their job.
Meta’s engineering team will then grant access, and they can read users’ messages in near real-time. Furthermore, access is unlimited in time, with Meta employees able to access messages from the time users first activated their accounts, including those messages that users believe they have deleted.”
See also: Meta tests premium subscriptions on Instagram, Facebook and WhatsApp

These are significant allegations, and would be one of the biggest privacy scandals, if proven true.
Johns Hopkins University: What does an expert say on the subject?
Johns Hopkins University professor and cryptographer Matthew Greenhas written an extensive post on the subject. He notes that while WhatsApp's encryption is based on the Signal, the actual code used is not open source, making it impossible for independent researchers to verify how it's implemented.
“Unfortunately, WhatsApp is closed source, which means you can't easily download the source code to see if encryption is being performed properly or not“.
However, he says it is extremely unlikely that the claims are true, for three reasons.
“I can't tell you for sure that this isn't happening. I can, however, tell you that if WhatsApp did this, (1) they would have caught it, (2) the data would almost certainly be visible in WhatsApp's application, and (3) it would have exposed WhatsApp and Meta to significant risks..
Even though the source code of the WhatsApp app is not public, many historical versions of the compiled app are available for download. You can download one now and decompile it using various tools to see if your data or keys are being extracted.”
See also: WhatsApp: Three new features in group chats

Green acknowledges that performing this analysis would be a large task, but it can be done and would create a big problem for Meta if it were proven to be lying about WhatsApp's end-to-end encryption.
