Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hugface CEO says we’re in an ‘LLM bubble’, not an AI bubble

Sneaky 2FA phishing kit adds BitB pop-up designed to mimic browser address bar

Hank Green’s Focus Friend named Google Play’s app of the year

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Meta expands WhatsApp security investigation with new proxy tools and $4 million bounty this year
Identity

Meta expands WhatsApp security investigation with new proxy tools and $4 million bounty this year

userBy userNovember 18, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 18, 2025Ravi LakshmananBug Bounty / Data Privacy

Meta announced Tuesday that it has provided a tool called WhatsApp Research Proxy to some researchers who have long offered bug bounties to help them improve their programs and more effectively investigate the messaging platform’s network protocols.

The aim is to make it easier to explore WhatsApp’s unique technology, as it remains a lucrative attack surface for state-sponsored attackers and commercial spyware vendors.

The company also noted that it is launching a pilot initiative to invite a research team to focus on exploiting the platform, with support from in-house engineering and tools. “Our goal is to lower the barrier for academics and other researchers who are less familiar with bug bounties to participate in our program,” he added.

DFIR retainer service

The development comes after the social media giant announced that it has awarded more than $25 million in bug bounties to more than 1,400 researchers in 88 countries over the past 15 years, with more than $4 million paid out this year alone for around 800 valid reports. According to Meta, a total of about 13,000 applications were received.

Some of the notable bug findings include an incomplete validation bug in WhatsApp before WhatsApp v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 that could allow a user to trigger processing of content retrieved from any URL on another user’s device. There is no evidence that this issue has been exploited in the wild.

Meta has also released an operating system level patch to mitigate the risk posed by the vulnerability tracked as CVE-2025-59489 (CVSS score: 8.4). This vulnerability could allow a malicious application installed on a Quest device to manipulate Unity applications and execute arbitrary code. Flatt Security researcher RyotaK is credited with discovering and reporting this flaw.

3.5 billion phone numbers exposed due to simple security flaw in WhatsApp

Finally, Meta said it has added anti-scraping protection to WhatsApp following a report detailing a new way to massively enumerate WhatsApp accounts from 245 countries and bypass the service’s rate-limiting restrictions to build a dataset that includes all users. WhatsApp has around 3.5 billion active users.

This attack takes advantage of the legitimate WhatsApp contact discovery feature, which requires users to first check if their contacts are registered on the platform. This essentially allows the attacker to edit basic publicly accessible information, along with the profile picture, About text, and timestamps associated with key updates related to the two attributes. Meta said it found no evidence that this vector was used in a malicious situation.

Interestingly, the study found that millions of phone numbers are registered with WhatsApp in countries where WhatsApp is officially banned, including 2.3 million in China and 1.6 million in Myanmar.

“Normally a system should not respond to so many requests in such a short period of time, especially if they are coming from a single source,” said Gabriel Gegenhuber, a researcher at the University of Vienna and lead author of the study. “This behavior exposed a fundamental flaw that allowed it to issue virtually unlimited requests to the server, and in doing so, map user data around the world.”

CIS build kit

“We are already working on industry-leading anti-scraping systems, and this research helped us stress test and confirm the immediate effectiveness of these new defenses,” Nitin Gupta, WhatsApp’s vice president of engineering, told Hacker News in a statement.

“Importantly, the researchers securely deleted the data they collected as part of their research, and we have found no evidence that malicious actors are exploiting this vector. As a reminder, thanks to WhatsApp’s default end-to-end encryption, users’ messages remain private and secure, and the researchers were unable to access any non-public data.”

Earlier this year, Gegenhuber and colleagues also demonstrated another study titled Careless Whisper, which showed how delivery receipts can pose significant privacy risks to users, allowing attackers to send specially crafted messages that can trigger delivery receipts and extract their activity status without the user’s knowledge or consent.

“By using this technique at high frequency, we demonstrated how attackers can extract personal information, including tracking users across different companion devices, inferring users’ daily schedules, and inferring their current activities,” the researchers said.

“Furthermore, it is possible to infer the number of currently active user sessions (main and companion devices) and their operating systems, and launch resource exhaustion attacks such as draining the user’s battery or data capacity, without generating notifications on the target side.”

(Article updated after publication to include a response from WhatsApp and clarify that CVE-2025-59489 was patched and published by Unity.)


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article‘From another world’: 3I/ATLAS drops photobombs on the galaxy, showing off its multiple tails in stunning new images
Next Article Google launches Gemini 3 with new coding apps and benchmark scores
user
  • Website

Related Posts

Sneaky 2FA phishing kit adds BitB pop-up designed to mimic browser address bar

November 18, 2025

Learn how leading enterprises protect cloud workloads and infrastructure at scale

November 18, 2025

Researchers detail Tuoni C2’s role in 2025 real estate cyber intrusion attempt

November 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hugface CEO says we’re in an ‘LLM bubble’, not an AI bubble

Sneaky 2FA phishing kit adds BitB pop-up designed to mimic browser address bar

Hank Green’s Focus Friend named Google Play’s app of the year

Google launches Gemini 3 with new coding apps and benchmark scores

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.