A recent report by Austrian researchers has uncovered a major flaw in WhatsApp, the popular messaging app with over 3.5 billion users worldwide. The vulnerability allowed anyone to easily obtain the phone numbers of nearly all WhatsApp users, along with access to their profile photos and text. This massive exposure highlights the ongoing risks of data privacy and security, especially for a service used by billions of people daily.
How Did This Happen?
The researchers found that WhatsApp’s system allowed anyone to extract phone numbers by simply trying to add them as contacts. When a phone number was entered into WhatsApp, the app would tell the user if the number was linked to an active WhatsApp account. Additionally, WhatsApp would display profile photos and text associated with the account, even if the account was set to “public.” This meant that anyone could potentially access these details without any specialized skills or tools—no black-hat hacking required.
Using WhatsApp Web, the browser-based interface for WhatsApp, the researchers were able to check approximately 100 million phone numbers per hour. The process was entirely automated, allowing them to uncover details for millions of users. Despite Meta, WhatsApp’s parent company, being warned about this issue as far back as 2017 by a different researcher, it took years before any action was taken to secure the data.
What Was Exposed?
For 57% of the 3.5 billion WhatsApp users, the researchers were able to access profile photos, and for 29%, they could see text on their profiles. While Meta, which owns WhatsApp, maintains that this is publicly available information and wasn’t private data, it still raises serious concerns about privacy, especially when users are unaware of the ease with which their personal data can be accessed.
The researchers did not access any non-public data from WhatsApp users, and Meta has stressed that users who had set their profile photos or text to private were not affected. However, given the scale of the exposure, this vulnerability has opened the door for potential exploitation by malicious actors, particularly in phishing or spam campaigns.
Meta’s Response to the Discovery
Meta responded to the researchers’ findings by confirming the vulnerability and stating that it had taken steps to address it. In April 2025, the researchers notified Meta about the issue, and by October 2025, the company implemented rate-limiting on WhatsApp Web to prevent such mass-scale discovery of phone numbers. Rate-limiting reduces the number of requests that can be made to WhatsApp’s servers in a given period, making it harder for automated tools to extract large volumes of data.
Meta emphasized that, despite the large exposure, no malicious actors had been found to exploit the vulnerability during the period it was open. The company also reassured users that it did not find evidence of any significant abuse, though this has not alleviated the concerns about the security of such a massive user base.
The Bigger Picture: Data Privacy and Security
This breach underscores the broader concerns surrounding data privacy and the risks of over-sharing information online. While the exposed data in this case may be considered basic or publicly available, it highlights the need for stronger protections against accidental leaks. As services like WhatsApp become more ingrained in daily life, it becomes increasingly important for companies to safeguard users’ data proactively rather than reactively.
The fact that this issue remained unresolved for several years speaks to the challenges in data privacy in the modern age, where automated tools can quickly exploit vulnerabilities. It also raises questions about the responsibility companies like Meta have in ensuring that user data is kept secure—especially when millions of people’s personal information is at stake.
Conclusion: What’s Next for WhatsApp Users?
While Meta has addressed the issue with a rate-limiting update, the incident highlights the need for ongoing vigilance in securing user data. Users should be aware of the information they make public on social platforms like WhatsApp and take steps to secure their accounts through settings such as profile privacy options and two-factor authentication (2FA). The WhatsApp phone number exposure debacle serves as a stark reminder of how easily personal data can be accessed and the importance of digital security in protecting users’ privacy.








