Interview on WhatsApp: From Emojis to the Mega Data Leak

November 27, 2025 at 03:13 PM UTC
netzpolitik.org
Original: DE
Interview on WhatsApp: From Emojis to the Mega Data Leak

A research group from the University of Vienna and SBA Research uncovered a massive data leak affecting WhatsApp, exposing 3.5 billion user profiles. This incident highlights significant vulnerabilities in the popular messaging platform and raises critical questions about data protection practices in the digital age. The researchers were able to collect this data through a previously unknown security flaw. The researchers exploited a vulnerability in WhatsApp's interface, allowing them to enumerate and collect data associated with a vast number of phone numbers. They used a program that compared a catalog of generated phone numbers against WhatsApp's user directory. The data collected included profile pictures, "info text," and public keys. Crucially, there was no rate-limiting, meaning the number of queries was not restricted, enabling the researchers to gather information on a massive scale. This data breach has significant implications for user privacy, particularly as the collected profiles contained information about users in countries where WhatsApp is banned. The researchers' findings underscore the potential risks associated with the handling of user data by digital platforms, emphasizing the need for robust security measures and strict adherence to data protection regulations like GDPR. The incident serves as a reminder of the importance of digital privacy. The researchers disclosed the vulnerability to Meta, WhatsApp's parent company, which subsequently patched the security flaw. The study, which details the findings, has been published after the closure of the security gap. This raises awareness for future security measurements and a better understanding of digital risks.

To provide multilingual access, this article summary was automatically generated.

Source Information

Publication: netzpolitik.org
Published: November 27, 2025 at 03:13 PM UTC
All rights remain with the original publisher.

European Alternatives You Might Like

Pixelfed logo

Pixelfed

Pixelfed is a decentralized, open-source social media platform for sharing images. Users can upload and share photos, follow other users, and interact through likes, comments, and shares. Utilizing the ActivityPub protocol, Pixelfed allows for federation, enabling users to interact with individuals on other compatible platforms. It is designed for photographers and anyone seeking a privacy-focused, community-driven alternative to centralized image-sharing services.

Element (Matrix) logo

Element (Matrix)

Element is a secure, decentralized communication platform built on the Matrix protocol. It allows users to send end-to-end encrypted messages, share files, and participate in group chats. Key features include voice and video calls, bridging with other communication platforms like Slack and Discord, and the ability to host your own server for enhanced privacy and control. Element is suitable for individuals, teams, and organizations seeking secure and private communication, and is particularly beneficial for those who value data sovereignty and open-source solutions.

CryptPad logo

CryptPad

CryptPad is an end-to-end encrypted online office suite offering collaborative document creation and editing. It provides functionalities similar to other office suites, including text documents, spreadsheets, presentations, and code editors, all with a priority on user privacy. Unique features include its zero-knowledge architecture, which prevents the server from accessing user data, and its open-source nature, which allows for independent audits and community contributions. This makes it suitable for individuals and teams seeking secure and private online collaboration, especially those who prioritize data confidentiality.

SoundCloud logo

SoundCloud

SoundCloud is a digital audio distribution platform where users can upload, promote, and share their original music and audio. Key features include music streaming, direct messaging, commenting, and the ability to follow artists and playlists. This platform is primarily used by independent musicians, DJs, and podcasters to share their work, connect with listeners, and build an audience. SoundCloud offers a vast library of user-generated content, providing access to a wide range of music and audio not always available on other streaming services.