CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

WhatsApp API Flaw Enabled Large-Scale User Enumeration

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Researchers exploited a WhatsApp API flaw to scrape 3.5 billion active accounts by abusing the contact-discovery feature. The lack of rate limiting allowed them to query over 100 million numbers per hour, gathering profile photos, 'about' text, and device information. WhatsApp has since added rate-limiting protections to prevent similar abuse. The study highlights a common tactic used by threat actors to scrape user information from unprotected APIs, with similar incidents occurring on Facebook, Twitter, and Dell.

Timeline

  1. 22.11.2025 20:53 1 articles · 23h ago

    WhatsApp API Flaw Enabled Large-Scale User Enumeration

    Researchers exploited a WhatsApp API flaw to scrape 3.5 billion active accounts by abusing the contact-discovery feature. The lack of rate limiting allowed them to query over 100 million numbers per hour, gathering profile photos, 'about' text, and device information. WhatsApp has since added rate-limiting protections to prevent similar abuse.

    Show sources

Information Snippets