By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Pixel PakistanThe Pixel PakistanThe Pixel Pakistan
Font ResizerAa
  • Home
  • Exclusive
  • Tech
  • Political
  • News
  • Fashion
  • Business
  • Sports
  • Music
  • Films
Reading: WhatsApp Bug Exposed Phone Numbers of Over 3.5 Billion Users
Font ResizerAa
The Pixel PakistanThe Pixel Pakistan
  • Home
  • Tech
  • Political
  • Sports
  • News
  • Fashion
  • Contact
  • Privacy Policy
  • Terms & Conditions
Search
  • Home
  • Exclusive
  • Tech
  • Political
  • News
  • Fashion
  • Business
  • Sports
  • Music
  • Films

Trending →

Dhurandhar Trailer Sparks Debate Over Pakistan’s Portrayal

By
The Pixel Pakistan Publisher
November 19, 2025

Chinese SUV Brand Jetour Officially Launches in Pakistan

By
Syed Mehmood
November 19, 2025

WhatsApp Bug Exposed Phone Numbers of Over 3.5 Billion Users

By
Syed Mehmood
November 19, 2025

NTC Successfully Thwarts Two Major Cyber Attacks on Government Institutions

By
Syed Mehmood
November 19, 2025

Investigation Reveals Unremovable Software on Samsung Galaxy A and M Series Devices

By
Syed Mehmood
November 19, 2025
Follow US
© 2025 The Pixel Pakistan. All rights reserved.
whatsapp toxic ezgif.com webp to jpg converter
Tech

WhatsApp Bug Exposed Phone Numbers of Over 3.5 Billion Users

Syed Mehmood
Last updated: November 19, 2025 6:14 pm
By
Syed Mehmood
Share
4 Min Read
SHARE
chrome

A new security study has revealed that the widely-used messaging platform WhatsApp was vulnerable to mass enumeration of user phone numbers, potentially exposing 3.5 billion accounts across the globe

Contents
  • What Went Wrong
  • Meta / WhatsApp’s Response
  • Why the Issue Matters for Pakistan and Beyond
  • What Users & Organisations Should Do

What Went Wrong

Researchers from the University of Vienna and associated security teams discovered that WhatsApp’s “contact discovery” function—which allows users to check whether a phone number has a WhatsApp account—could be abused at very large scale.

By systematically submitting billions of phone-number queries, they were able to identify active accounts and, for a large portion, public profile photos and status text. Their findings include:

  • Over 3.5 billion distinct WhatsApp user accounts enumerated worldwide.
  • For approximately 57% of those accounts, profile pictures (when publicly set) were also accessible.
  • For about 29%, public profile status text (“About” field) could be discovered.
  • The enumeration exploited a lack of rate-limiting, allowing the researchers to test tens of millions to hundreds of millions of numbers per hour from a single server.

Meta / WhatsApp’s Response

Meta Platforms, the parent company of WhatsApp, responded by saying the data exposed was “basic publicly-available information,” such as phone numbers and public profile elements, and indicated they found no evidence of malicious exploitation.

Meta noted that as of October 2025 they have implemented stricter rate-limiting to prevent large-scale enumeration.

Why the Issue Matters for Pakistan and Beyond

  • Privacy at scale: With over 3 billion monthly active users reported for WhatsApp globally, this issue touches a significant portion of the world’s mobile communications.
  • Target-rich environment: In countries like Pakistan where WhatsApp is widely used both for personal and business communication, exposed phone numbers plus public profile data increase risk of spam, targeted scams, social engineering and identity threats.
  • Risk in restricted jurisdictions: The researchers found active WhatsApp accounts in countries where the platform is banned (e.g., China, Myanmar, Iran) — meaning enumeration could aid surveillance of dissidents or blocked communities.
  • Design flaw over time: The vulnerability stemmed from a feature designed for ease of finding contacts. Researchers pointed out that Meta had been warned in 2017 about similar enumeration risks, yet the issue remained unmitigated for years.

What Users & Organisations Should Do

  • Change privacy settings: Users should restrict who can see their profile picture, status and “about” text. Even if phone numbers are known, limiting metadata helps.
  • Use alternate identifiers: Whenever supported, move away from using phone-number as the only public identifier, especially for business or public-facing accounts.
  • Remain vigilant for spam/phishing: With numbers potentially selectable en-masse, risk of targeted scam campaigns increases — organisations should educate employees around suspicious messages.
  • For businesses using WhatsApp-based services: review any integration that exposes the business’s or customers’ phone numbers and ensure privacy design is strong.

While the flaw has been mitigated, the incident underscores a broader message: even highly trusted, end-to-end encrypted platforms can leak metadata at scale via unintended avenues. For developers and security teams, the takeaway is to treat phone numbers as identifiers with care, implement stricter rate-limiting on enumeration logic, and monitor public-facing discovery features aggressively.

For regulators and policymakers in Pakistan and other markets, this could trigger revisions in telecom and data-privacy rules, especially around how mobile platforms protect metadata and restrict large-scale data harvesting.

Share This Article
Facebook Whatsapp Whatsapp Threads Copy Link
What do you think?
Love0
Sad0
Happy0
Angry0

Follow Us

- Advertisement -

The Pixel Pakistan

More

Gemini Generated Image hrknibhrknibhrkn
Dhurandhar Trailer Sparks Debate Over Pakistan’s Portrayal
Films
Jetourdashing x70plus ezgif.com webp to jpg converter
Chinese SUV Brand Jetour Officially Launches in Pakistan
Exclusive
17635330221130
NTC Successfully Thwarts Two Major Cyber Attacks on Government Institutions
Tech
G58C1scbsAA0Q0o
Investigation Reveals Unremovable Software on Samsung Galaxy A and M Series Devices
Exclusive

You Might Also Like ↷

GITEX Dubai 750x350 1

NITB to Showcase Pakistan’s Digital Transformation at GITEX 2025

By
Syed Mehmood
October 14, 2025
deep web cover

PTA Chairman Confirms Pakistani Data Available on Dark Web, Contradictions Emerge

By
Syed Mehmood
September 19, 2025
Picture of State bank of Pakistan Museum

Millions at Risk as JazzCash, Easypaisa Accounts Face Biometric Deadline

By
Syed Mehmood
October 27, 2025
META

Meta Expands Facial Recognition to Combat Celebrity Impersonator Accounts

By
Syed Mehmood
October 2, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles and deals instantly!
  • About Us
  • Careers
  • Advertise with us
  • Contact
  • Privacy Policy
  • Terms & Conditions
Pixel Pakistan is the voice of today and the vision of tomorrow, a platform that frames the evolving picture of our nation with clarity and depth. More than just news, it is a space where truth, inquiry, and understanding come together to inspire fresh perspectives and progress.
The Pixel Pakistan
393.9kFollowersLike
34.3kFollowersFollow
InstagramFollow
4.42MSubscribersSubscribe
TiktokFollow
30.4kFollowersFollow
LinkedInFollow
RSS FeedFollow

© 2025 The Pixel Pakistan. All rights reserved.