Skip to main content
See every side of every news story
Published loading...Updated

WhatsApp Had a Massive Security Flaw that Put Phone Numbers of 3.5 Billion Users at Risk: Here's What Happened

A vulnerability exploited via WhatsApp Web allowed automated harvesting of 3.5 billion phone numbers, with 57% of users' profile photos publicly visible, prompting privacy reviews.

  • Yesterday, a team of Austrian researchers revealed they compiled phone numbers for all 3.5 billion WhatsApp accounts, prompting coverage on cybersecurity channels including Cyber Security News.
  • Researchers automated WhatsApp Web contact-discovery to scale normal adds without exploits, exploiting the feature’s linked profile photos, status display, and weak scraping limits.
  • At peak speed, their system tested nearly 100 million numbers per hour, with 57% publicly visible profile photos and 29% accessible profile text, requiring no hacking tools.
  • Meta added strict rate-limiting in October 2025 after the April 2025 disclosure and said the exposed data was basic publicly available information with no evidence of abuse.
  • Alerts trace back to 2017, raising concerns that years of exposure allowed data harvesting, and users who rely on WhatsApp daily should review privacy settings to reduce risks.
Insights by Ground AI

25 Articles

Center

Viennese researchers crack WhatsApp: 3.5 billion mobile phone numbers and profile images could be accessed in a few months. Meta reacts.

Read Full Article
Center

A simple and common gesture in the daily life of those who have a telephone, that is, checking WhatsApp contacts, can be used to obtain information and personal data on...

Read Full Article
Lean Right

Italy is in the 15th place of the ranking of the most affected countries, with over 55 million accounts

·Italy
Read Full Article
Center

According to a study conducted by the University of Vienna, a basic functionality of the messaging app has endangered billions of people around the globe. And Meta was already aware of this in 2017

·Italy
Read Full Article
Lean Left

The flaw was exploited by a group of researchers who warned Meta. The company minimized the potential gravity of the incident but a precedent that...

·Turin, Italy
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 64% of the sources are Center
64% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Live Mint broke the news in New Delhi, India on Wednesday, November 19, 2025.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal