A serious privacy flaw in WhatsApp let researchers map out 3.5 billion accounts and user phone numbers worldwide, thanks to a loophole in the app’s system.
The critical vulnerability, discovered by computer scientists at the University of Vienna and SBA Research, even allowed millions of WhatsApp accounts to be identified in countries where the platform is officially banned, such as China, Iran, and Myanmar, raising concerns about user safety.
To find other WhatsApp users by phone number, the app runs a search against a phone’s internal contacts list, but researchers found this underlying mechanism could be abused to query more than 100 million phone numbers an hour, allowing them to confirm over 3.5 billion active accounts in 245 countries.
“Under normal circumstances, such a large number of requests from a single source or server should not be processed,” said Gabriel Gegenhuber, a researcher at SBA Research and lead author of the study.
“That was the vulnerability: we were able to send virtually unlimited requests to the server and thus conduct a global enumeration. These results remind us that even mature and widely trusted systems can contain design or implementation flaws with real-world consequences.”
As WhatsApp messages are end-to-end encrypted, users’ message content was never accessed or affected, but the study found that, in a few cases, cryptographic keys were reused across different devices or phone numbers, suggesting weaknesses in unofficial WhatsApp clients or fraudulent use.
As well as phone numbers and public keys, the collected data also hoovered up users’ profile photos, if set to public. By analysing such data points, the security specialists were able to infer metadata such as the user’s device operating system, the age of the account, and the number of linked secondary devices.
Perhaps most worrying, the study identified more than two million Chinese WhatsApp users, where use of the app is blocked by the Great Firewall as the government looks to maintain strict control over the flow of information, as well as fifty-nine million active accounts in Iran, roughly two-thirds of the population.
More troubling, researchers were able to see users’ About Text, the tag lines, which, while typically left as the default Hey there! I am using WhatsApp, in some instances, provided limited insight into users’ political ideology, sexuality, and religious beliefs.
On top of all that, nearly half of the 500 million phone numbers exposed in Facebook’s 2021 data leak were found to still be active on WhatsApp, a stark reminder of the long-term threat posed by leaked personal data.
Recommended reading
- 60% of Businesses Anticipating a Cyber-breach in 2025
- VPN Security Fears Pushing Firms To ‘Zero Trust Everywhere’
- Growing Adoption of Zero-trust and Multi-cloud Environments
The good news is that Meta has already worked with the researchers to address these security gaps.
“This collaboration successfully identified a novel enumeration technique that surpassed our intended limits, allowing the researchers to scrape basic publicly available information,” said Nitin Gupta, VP of engineering at WhatsApp.
“We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defences.
“Importantly, the researchers have securely deleted the data collected as part of the study, and we have found no evidence of malicious actors abusing this vector.”
Don’t Miss Scotland’s Largest Tech Event of the Year – DIGIT Expo: 27th November
50 Speakers – 40 Exhibitors – 2000 Delegates
Don’t miss DIGIT Expo, Scotland’s largest annual tech gathering, taking place at the EICC in Edinburgh on 27th November. We have a stacked conference agenda with 5 Stages of leading edge content, including presenters from Microsoft, Amazon, Spotify, Morgan Stanley, Alibaba, and NVIDIA…
Register now at: https://digit-expo.com/





