WhatsApp Security Flaw Exposed Billions of Phone Numbers: Details

A group of researchers were able to extract 3.5 billion phone numbers and associated WhatsApp data.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 19 November 2025 19:27 IST
Highlights
  • Researchers checked a high volume of possible numbers on WhatsApp
  • They used automation to process these phone numbers
  • The researchers found that WhatsApp does not apply rate limits

Researchers said this is the most extensive exposure of phone numbers and profile data

Photo Credit: Unsplash/Mika Baumeister

WhatsApp's systemic flaw was exploited by a group of researchers to expose around 3.5 billion phone numbers and related account data. As per the study, the researchers took advantage of the fact that the Meta-owned platform does not apply any rate limits on showing profiles on a registered account, letting them process large datasets of possible phone numbers and checking if these numbers belonged to anyone. The researchers said this is the most extensive exposure of phone numbers and associated profile data ever documented, and in the wrong hands, could have led to a major security threat.

Researchers Expose 3.5 Billion WhatsApp Accounts

A team of researchers at the University of Vienna and SBA Research has uncovered a vulnerability in WhatsApp's contact-discovery system that enabled the enumeration of around 3.5 billion phone numbers and associated profile data. The research paper was published on GitHub and details their method, highlighting a critical security flaw in WhatsApp's system.

The method exploited the fact that WhatsApp allows users to upload a phone book and quickly see which contacts already have accounts. The researchers automated the process by systematically inserting large sets of possible phone numbers and recording whether each number was registered. Because the system did not enforce effective rate-limiting, they were able to check tens of millions of numbers per hour.

Advertisement

Their analysis shows that for many of the discovered numbers, additional public metadata was available. Specifically, about 57 percent of the accounts had profile photos that were visible to “everyone,” and roughly 29 percent included text in the “About” field of the profile.

Advertisement

Interestingly, researchers also identified millions of accounts in countries where WhatsApp is banned. They found 2.3 million accounts in China, 1.6 million accounts in Myanmar, and about 60 million accounts in Iran by using phone-number ranges for those countries. “Phone numbers were not designed to be used as secret identifiers for accounts, but that's how they're used in practice,” a researcher was quoted as saying by Wired.

According to Wired, the researchers reached out to Meta to highlight the enumeration problem, which was then fixed by the company in October. Meta reportedly stated that the exposed information was “basic publicly available information” and that no message content or private data was accessed.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. BSNL Rs. 107 Prepaid Plan Validity Reduced Again: See New Validity, Benefits
  2. Wobble One Launched in India With Dimensity 7400 SoC at This Price
  3. HMD Terra M Launched With Up to 10-Day Battery Life, IP69K Rating
  4. PS5 Gets Rs. 5,000 Discount in India During Sony's Black Friday Sale
  5. No Company Is Immune: Google CEO Sundar Pichai on AI Bubble Bursting
  6. Poco F8 Ultra Design, Features Leaked; Company Reveals Battery Details
  7. Vivo V60e Review
  8. Google Play Best of 2025: Here Are the Top Apps and Games in India
  9. Apple Announces New Annual and Monthly AppleCare+ Plans in India
  1. WhatsApp Security Flaw Exposed Billions of Phone Numbers: Details
  2. EA Sports Will Skip F1 Game in 2026 and Instead Release Paid Expansion for F1 25
  3. Most Common Passwords in 2025: ‘123456’ and ‘Admin’ Tops the List, Research Says
  4. Google CEO Sundar Pichai Speaks on AI Bubble, Says No Company Is Immune: Report
  5. Swiss Crypto Bank AMINA Granted Hong Kong Licence to Serve Institutions
  6. Samsung Partners AU Small Finance Bank to Add Tap & Pay Support For AU Visa Credit Cards
  7. Cloudflare Explains How Configuration Change Took Down 20 Percent of the Internet
  8. HMD Terra M Launched With Up to 10-Day Battery Life, MDM Support and IP69K Rating: Availability, Features
  9. Google Play Best of 2025: District by Zomato, CookieRun Among Top Apps and Games on Play Store in India
  10. Wobble One Launched in India With MediaTek Dimensity 7400 SoC, 50-Megapixel Rear Camera: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.