Researchers from the University of Vienna collected data on 3.5 billion WhatsApp users, taking advantage of a vulnerability in the web version of the service: it made it possible to check for accounts by phone number and see the name and profile photo with open privacy settings, writes Wired. At the same time, there were no restrictions on the frequency of requests to the server (rate limits) in the service, which made it possible to check up to 100 million numbers per hour.
As a result, scientists collected user numbers even from those regions where WhatsApp was blocked. 57% of users had visible profile photos, 29% had visible statuses. The latter was related to the privacy settings of the users themselves.
Researchers also identified duplicate cryptographic keys in some accounts, which theoretically makes it possible to decrypt other people’s correspondence. Scientists have linked this problem to the use of unofficial messenger clients.
The Meta company, which owns WhatsApp, has already introduced a restriction on accessing the server, but the user’s phone number still remains available in the profile, and there is no way to hide it. It is noted that this Meta vulnerability has been known at least since 2017 (then the company was still called Facebook).