Security researchers from the University of Vienna have uncovered a critical vulnerability in WhatsApp that allowed them to enumerate phone numbers of 3.5 billion users worldwide, exposing a massive privacy flaw in the world’s most popular messaging platform.
The security flaw stems from WhatsApp’s contact discovery mechanism, which enables users to check if their contacts are registered on the platform.
Researchers exploited weak rate-limiting protections to probe over 100 million phone numbers per hour without encountering blocking or effective rate-limiting measures.
Using reverse-engineered WhatsApp APIs, the team systematically queried 63 billion candidate phone numbers across 245 countries between December 2024 and April 2025.
Massive Data Exposure Beyond Phone Numbers
The vulnerability exposed far more than just phone numbers. Researchers retrieved public profile pictures, status messages, business account information, device details, encryption keys, and timestamps for discovered accounts.
Most alarmingly, they successfully downloaded 77 million public profile pictures from accounts with US phone numbers, with facial recognition analysis revealing that 66 percent contained detectable human faces.
This data could enable malicious actors to construct a facial recognition-based lookup service linking individuals to their phone numbers.
The research revealed particularly concerning implications for users in countries where WhatsApp is officially banned.
Researchers discovered 2.3 million active accounts in China, 1.6 million in Myanmar, and 59 million in Iran despite government restrictions.
In regions where messaging apps are prohibited, such information could carry serious consequences for users, potentially exposing them to government surveillance or legal penalties.
By comparing their dataset with the 2021 Facebook data leak, which contained 500 million records, researchers found that nearly half of the leaked phone numbers remained active on WhatsApp six years later.
This demonstrates the long-lasting nature of data breaches and highlights how once-exposed information continues to pose security risks for extended periods.
The persistent validity of leaked data makes it a reliable foundation for spam campaigns, phishing attacks, and robocalls.
Following responsible disclosure, WhatsApp collaborated with the team to implement multiple countermeasures, including cardinality-based rate limiting using probabilistic data structures, restricting access to profile pictures and status messages even when set to public, and removing timestamps from profile picture queries.
The company also fixed a key reuse vulnerability in Android clients. WhatsApp stated that user messages remain protected through default end-to-end encryption and thanked researchers for their collaboration on mitigation testing.
The discovery underscores fundamental privacy challenges in centralized messaging platforms and demonstrates how design features intended for user convenience can become security vulnerabilities when inadequately protected against abuse at scale.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates