HomeSecurityWhatsApp: Save unencrypted chat history on iPhone and Mac

WhatsApp: Save unencrypted chat history on iPhone and Mac

New privacy questions are being raised by cybersecurity researchers' revelations about how WhatsApp stores chat data on Apple devices . According to the findings, chat histories may be stored locally without full encryption on iPhone, iPad and Mac, despite the fact that the platform uses end-to-end encryption to protect messages in transit.

WhatsApp

The issue was brought to light by iOS security researchers Mysk, who claim that WhatsApp leaves decrypted data exposed in local SQLite databases. The revelation brings back to the forefront a debate that has been plaguing the cybersecurity community for years: how secure data remains once it finally reaches a user's device.

Encryption stops when the message reaches the device

WhatsApp has long been considered one of the most secure messaging apps thanks to its strong end-to-end (E2EE) encryption. This technology ensures that only the sender and recipient can read messages as they travel over the internet.

See also: Wireshark 4.6.6 fixes ROHC Parser vulnerabilities

However, the researchers point out that this protection does not necessarily cover how the data is stored after decryption on the device.

According to the report, WhatsApp uses a SQLite database called “Axolotl.sqlite” to store conversations and metadata. The file appears to be located in a shared application container labeled “group.net.whatsapp.WhatsApp.shared.”

This means that other apps that belong to the same developer ecosystem — theoretically Meta apps like Facebook or Instagram — could access the data if they have the corresponding access rights.

Why the issue is of concern to security experts

Experts emphasize that the problem does not concern the interception of messages during their transport, but the so-called “encryption at rest”.

Simply put, while messages travel securely over the internet, decrypted data may remain readable on the device.

This creates a number of potential risks. In the event of a device being compromised, jailbroken, or a malicious application with access to the same shared container, the chat history could theoretically be extracted or read without much difficulty.

The problem appears to be even more severe on macOS, where the operating system offers more flexibility in accessing the file system than iOS. If endpoint security mechanisms are not sufficiently strong, the chances of accessing sensitive data increase significantly.

See also: Ghost CMS vulnerability: 700+ sites compromised and ClickFix attacks

WhatsApp: Save unencrypted chat history on iPhone and Mac

Apple's architecture and shared containers

It's worth noting, however, that this behavior is not technically considered a violation of Apple's sandboxing model. Shared app containers are an official mechanism in iOS and macOS that allows apps from the same developer to exchange data.

The real issue is whether the data stored there should remain additionally encrypted at the application level.

Apple already has data protection mechanisms that can encrypt files when the device is locked, but the researchers point out that this is not always enough to prevent access by other authorized apps within the same ecosystem.

The case highlights a broader problem facing the technology industry as a whole: data security depends not only on encryption in transit but also on its secure storage on the devices themselves.

What WhatsApp users can do for greater protection

Although there is no public evidence so far that Meta is exploiting this access capability, experts recommend caution, especially for users who handle sensitive information.

Using strong passwords, Face ID, and biometrics remains a basic line of defense. At the same time, it is recommended to avoid installing unnecessary applications that belong to the same developer ecosystem.

See also: Supply-chain: 84 infected TanStack versions uploaded in 6 minutes

WhatsApp: Save unencrypted chat history on iPhone and Mac

In corporate environments, mobile device management (MDM) solutions can significantly restrict app permissions and reduce data leakage risks.

At the same time, this revelation will likely intensify pressure on major messaging platforms to adopt stronger local encryption mechanisms.

As communications services increasingly promote the privacy narrative, users and security experts are now turning their attention not only to how data is transmitted, but also to where and how it is stored after it is decrypted.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS