started · updated
WhatsApp and Signal face security flaws affecting privacy
Researchers have identified security vulnerabilities in WhatsApp and Signal that could allow attackers to track a user's approximate location and usage patterns using only a phone number. A study led by Max Günter from the University of Vienna highlights a flaw in the message delivery notification mechanism. By measuring the Round Trip Time (RTT)—the interval between a message reaching the app server and the delivery confirmation returning from the recipient's device—attackers can infer whether a device is active, in standby mode, or has its screen turned off.
Additionally, vulnerabilities have been identified regarding WhatsApp's multi-device architecture. While the app uses end-to-end encryption (E2EE) to protect data in transit, Tal Berry, CTO of Zengo, noted that the synchronization of multiple devices (such as smartphones, PCs, and tablets) creates new attack vectors. These structural gaps may allow attackers to identify a target's specific operating system, enabling more precise malware delivery. Because delivery notifications function automatically upon a message reaching a device, users may be subject to data collection without ever opening the message.