Major WhatsApp Flaw Exposed Numbers and Photos of Nearly All Users
A security research team from the WhatsApp platform uncovered a massive privacy lapse. They managed to extract phone numbers—and in many cases profile photos and status texts—of approximately 3.5 billion users worldwide.
The root cause? A seemingly benign “contact discovery” tool built into WhatsApp. It’s meant to make it easy for users to find friends on the service—yet it could be abused at scale. The researchers could check tens of millions of numbers per hour and collect data without being blocked.
MORE ARTICLES:
How it worked: Simple tool, immense impact
-
WhatsApp’s contact‑discovery feature lets users upload their address book and see who is on WhatsApp. That’s normal.
-
The flaw: There was no strict limit on how many numbers one could query, and the system responded with whether a number was registered, and sometimes returned the profile photo or status text.
-
Using automated scripts, the researchers queried billions of possible numbers—across 245 countries—and assembled a database of active accounts, photos and text statuses.
-
Among the findings: about 57 % of the accounts had profile photos accessible, and roughly 29 % had “about” text visible.
The response: WhatsApp notices, fixes follow
After being alerted in April 2025, WhatsApp’s parent company Meta Platforms said it introduced rate‑limiting of queries by October 2025 to block bulk access.
Meta’s official stance: Although the data accessed was “basic publicly available information,” they claim no evidence shows the flaw was exploited maliciously. Still, the scale of exposure is alarming.
Why this matters to you
-
Privacy risk: Even if you did nothing wrong, knowing your phone number may be accessible—and your profile image may have been scraped—doesn’t feel great.
-
Scams & impersonation: With large databases of numbers and publicly visible profile data, scammers can craft more convincing messages that appear trusting.
-
Global reach: This was not limited to one region—countries with large user bases such as India, Brazil and many more were impacted.
-
Underlying warning sign: It’s a wake‑up call for all of us. Even widely‑used apps trusted for privacy can have structural flaws.
What you can do right now
-
Go into WhatsApp’s privacy settings: Set profile photo visibility to “My Contacts” or “Nobody”.
-
Minimise sharing of personal info in status or “About” text—treat it like public data.
-
Be cautious of surprising messages or calls from new numbers claiming they know you—scrapped profile info can lend credibility.
-
Keep your app and OS updates current—platforms often patch after a flaw becomes public.
-
Consider alternative identifiers: Use usernames or second numbers for more sensitive communications.
What’s next & how this could lead to bigger shifts
-
Companies may slowly move away from phone‑number‑based identity to usernames or unique IDs, which are harder to bulk‑scrape. In the research, phone‑number reuse and enumeration were major issues.
-
Platforms like WhatsApp may face greater regulatory scrutiny — especially in privacy‑focused regions.
-
Users may grow more cautious and demand higher privacy standards—meaning apps will emphasise transparency and protection more.
Final word
This wasn’t a tiny slip‑up—it was a structural vulnerability that allowed the extraction of sensitive data on a global scale. While no messages or hidden chats were revealed, the fact that phone numbers, photos and status texts were accessible en masse is a serious concern. It’s a reminder: in the digital world, visibility can equate to vulnerability.