|
Navigation
Recherche
|
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers
mardi 18 novembre 2025, 15:59 , par Slashdot
The team warned Meta in April and deleted their data. The company implemented stricter rate-limiting by October to prevent such mass enumeration. Meta called the exposed information 'basic publicly available information' and said it found no evidence of malicious exploitation. The vulnerability had been identified before. In 2017, Dutch researcher Loran Kloeze published a blog post detailing the same enumeration technique. Meta responded then that WhatsApp's privacy settings were functioning as designed and denied him a bug bounty reward. The researchers collected 137 million U.S. phone numbers. In India, they found nearly 750 million numbers. They also discovered 2.3 million Chinese numbers and 1.6 million Myanmar numbers, despite WhatsApp being banned in both countries. The researchers analyzed the cryptographic keys and found some accounts used duplicate keys. They speculate this resulted from unauthorized WhatsApp clients rather than a platform flaw. Read more of this story at Slashdot.
https://yro.slashdot.org/story/25/11/18/1459209/a-simple-whatsapp-security-flaw-exposed-35-billion-p...
Voir aussi |
56 sources (32 en français)
Date Actuelle
mar. 18 nov. - 18:11 CET
|








