Cybersecurity researchers have issued a fresh alert for WhatsApp users after identifying a critical loophole that allowed access to billions of user profiles on the Meta-owned messaging platform.
A team from the University of Vienna and SBA Research reported that a weakness in WhatsApp’s contact-matching system enabled them to pull metadata from an estimated 3.5 billion accounts.
While message content remained protected under end-to-end encryption, the researchers said the flaw allowed them to gather extensive personal information, including phone numbers, approximate locations, device types and the age of user accounts.
The issue stemmed from WhatsApp’s built-in contact discovery feature, which helps users find other accounts through phone numbers. According to the research team, the system lacked safeguards to prevent large-scale automated queries.
As a result, they were able to run up to 100 million number checks per hour and eventually map data tied to billions of profiles across 245 countries.
Lead researcher Gabriel Gegenhuber noted that such a high volume of requests should normally trigger system limits. “The server continued to respond, revealing an unrestricted query loophole that let us compile global user data,” he said.
Meta, which collaborated with the researchers through its Bug Bounty programme, confirmed that the vulnerability has now been patched.
Nitin Gupta, WhatsApp’s Vice President of Engineering, said the findings helped stress-test the platform’s anti-scraping measures. He added that the data collected during the study has been securely deleted and that there is no indication the flaw was exploited by malicious actors.
Gupta also reiterated that WhatsApp’s encryption was never compromised. Still, the researchers warn that the incident highlights risks stemming from the concentration of global communications on a few platforms.
They were able to determine users’ operating systems, account longevity, the number of linked devices and, in countries such as the United States, Brazil and Mexico, their locations down to the state level – information that could increase exposure to scams or targeted cyberattacks.
Their findings also revealed unexpected patterns. Despite bans, millions of active WhatsApp accounts exist in countries like China, Iran and Myanmar. The team further discovered that half of the numbers exposed in the 2021 Facebook data leak are still active on WhatsApp. That breach, which included names, numbers, birthdates and location details of roughly 500 million users, resulted in a €265 million fine against Meta by Ireland’s Data Protection Commission.
Researchers cautioned that individuals using numbers previously compromised in that breach may face ongoing, elevated cybersecurity risks.



