By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Pixel PakistanThe Pixel PakistanThe Pixel Pakistan
Font ResizerAa
  • Home
  • Exclusive
  • Tech
  • Political
  • News
  • Fashion
  • Business
  • Sports
  • Music
  • Films
Reading: WhatsApp Bug Exposed Phone Numbers of Over 3.5 Billion Users
Font ResizerAa
The Pixel PakistanThe Pixel Pakistan
  • Home
  • Tech
  • Political
  • Sports
  • News
  • Fashion
  • Contact
  • Privacy Policy
  • Terms & Conditions
Search
  • Home
  • Exclusive
  • Tech
  • Political
  • News
  • Fashion
  • Business
  • Sports
  • Music
  • Films

Trending →

Pakistan’s Quiet Breakthrough in Global Optimization: The Enduring Legacy of the NEH Algorithm

By
Syed Mehmood
January 22, 2026

Systems Limited CEO Dumps 10 Million Shares in Major Insider Sale

By
Syed Mehmood
January 11, 2026

NVIDIA’s Open-Source AI Push Aims to Make Autonomous Driving Safer and More Transparent

By
Syed Mehmood
January 11, 2026

PKCERT, Kaspersky Sign MoU to Strengthen Cybersecurity in Pakistan

By
Syed Mehmood
January 11, 2026

Islamabad–Baghdad Defence Talks Spur New Export Interest

By
Syed Mehmood
January 11, 2026
Follow US
© 2025 The Pixel Pakistan. All rights reserved.
whatsapp toxic ezgif.com webp to jpg converter
Tech

WhatsApp Bug Exposed Phone Numbers of Over 3.5 Billion Users

Syed Mehmood
Last updated: November 19, 2025 6:14 pm
By
Syed Mehmood
Share
4 Min Read
SHARE
chrome

A new security study has revealed that the widely-used messaging platform WhatsApp was vulnerable to mass enumeration of user phone numbers, potentially exposing 3.5 billion accounts across the globe

What Went Wrong

Researchers from the University of Vienna and associated security teams discovered that WhatsApp’s “contact discovery” function—which allows users to check whether a phone number has a WhatsApp account—could be abused at very large scale.

By systematically submitting billions of phone-number queries, they were able to identify active accounts and, for a large portion, public profile photos and status text. Their findings include:

  • Over 3.5 billion distinct WhatsApp user accounts enumerated worldwide.
  • For approximately 57% of those accounts, profile pictures (when publicly set) were also accessible.
  • For about 29%, public profile status text (“About” field) could be discovered.
  • The enumeration exploited a lack of rate-limiting, allowing the researchers to test tens of millions to hundreds of millions of numbers per hour from a single server.

Meta / WhatsApp’s Response

Meta Platforms, the parent company of WhatsApp, responded by saying the data exposed was “basic publicly-available information,” such as phone numbers and public profile elements, and indicated they found no evidence of malicious exploitation.

Meta noted that as of October 2025 they have implemented stricter rate-limiting to prevent large-scale enumeration.

Why the Issue Matters for Pakistan and Beyond

  • Privacy at scale: With over 3 billion monthly active users reported for WhatsApp globally, this issue touches a significant portion of the world’s mobile communications.
  • Target-rich environment: In countries like Pakistan where WhatsApp is widely used both for personal and business communication, exposed phone numbers plus public profile data increase risk of spam, targeted scams, social engineering and identity threats.
  • Risk in restricted jurisdictions: The researchers found active WhatsApp accounts in countries where the platform is banned (e.g., China, Myanmar, Iran) — meaning enumeration could aid surveillance of dissidents or blocked communities.
  • Design flaw over time: The vulnerability stemmed from a feature designed for ease of finding contacts. Researchers pointed out that Meta had been warned in 2017 about similar enumeration risks, yet the issue remained unmitigated for years.

What Users & Organisations Should Do

  • Change privacy settings: Users should restrict who can see their profile picture, status and “about” text. Even if phone numbers are known, limiting metadata helps.
  • Use alternate identifiers: Whenever supported, move away from using phone-number as the only public identifier, especially for business or public-facing accounts.
  • Remain vigilant for spam/phishing: With numbers potentially selectable en-masse, risk of targeted scam campaigns increases — organisations should educate employees around suspicious messages.
  • For businesses using WhatsApp-based services: review any integration that exposes the business’s or customers’ phone numbers and ensure privacy design is strong.

While the flaw has been mitigated, the incident underscores a broader message: even highly trusted, end-to-end encrypted platforms can leak metadata at scale via unintended avenues. For developers and security teams, the takeaway is to treat phone numbers as identifiers with care, implement stricter rate-limiting on enumeration logic, and monitor public-facing discovery features aggressively.

For regulators and policymakers in Pakistan and other markets, this could trigger revisions in telecom and data-privacy rules, especially around how mobile platforms protect metadata and restrict large-scale data harvesting.

Share This Article
Facebook Whatsapp Whatsapp Threads Copy Link
What do you think?
Love0
Sad0
Happy0
Angry0

Follow Us

- Advertisement -

The Pixel Pakistan

More

0f9f9199 3b4f 4279 ac30 040aef0f9d79
Pakistan’s Quiet Breakthrough in Global Optimization: The Enduring Legacy of the NEH Algorithm
Tech
SystemLimited
Systems Limited CEO Dumps 10 Million Shares in Major Insider Sale
Business
nvidia alpamayo
NVIDIA’s Open-Source AI Push Aims to Make Autonomous Driving Safer and More Transparent
Tech
1000x563 Blog Kaspersky
PKCERT, Kaspersky Sign MoU to Strengthen Cybersecurity in Pakistan
Tech

Top 10 Coins

  • bitcoinBitcoin$75,989.00-2.13%
  • ethereumEthereum$2,252.51-1.54%
  • tetherTether$1.00-0.04%
  • binancecoinBNB$754.46-1.09%
  • rippleXRP$1.58-0.47%
  • usd-coinUSDC$1.00-0.01%
  • solanaSolana$97.83-4.40%
  • tronTRON$0.2862621.17%
  • staked-etherLido Staked Ether$2,261.73-3.76%
  • dogecoinDogecoin$0.1070381.04%
Powered by CoinGecko API

You Might Also Like ↷

Copilot.jpg

Windows Copilot Just Got 2 Major Free Upgrades — Here’s What You Can Do Now

By
Syed Mehmood
October 14, 2025
MindHYVE ai Partners with the Government of Pakistan

MindHYVE.ai Partners with Government of Pakistan to Build AI-Literate Generation

By
Syed Mehmood
October 8, 2025
What is a Firewall 1024x536 1

Pakistan’s Internet Firewall is Getting a Major Upgrade

By
Syed Mehmood
November 10, 2025
Jnm7yA7V3yjiFs5f5oQ83S

Red Hat Consulting Suffers Major Data Breach, Exposing 800+ Organizations Worldwide

By
Syed Mehmood
October 8, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles and deals instantly!
  • Write For Us
  • Careers
  • Advertise with us
  • Contact
Pixel Pakistan is the voice of today and the vision of tomorrow, a platform that frames the evolving picture of our nation with clarity and depth. More than just news, it is a space where truth, inquiry, and understanding come together to inspire fresh perspectives and progress.
The Pixel Pakistan
393.9KFollowersLike
34.3KFollowersFollow
InstagramFollow
4.4MSubscribersSubscribe
TiktokFollow
30.4KFollowersFollow
LinkedInFollow
RSS FeedFollow

© 2025 The Pixel Pakistan. All rights reserved.

  • Terms & Conditions
  • Privacy Policy
  • About Us