Skip to main content

Vulnerability in WhatsApp for Android allows others to read your conversations

whatsapp offline message facebook feature
Image used with permission by copyright holder

If you’re chatting in WhatsApp, you may not want to say anything too private. Double Think chief technology officer Bas Bosschert has discovered a glaring security flaw sure to put frowns on plenty of people’s faces.

Here’s what’s wrong: When you back up your WhatsApp data, possibly because you want to install the app on another device, the back-up goes to the WhatsApp database, which is saved on your phone’s SD card. Rather than make a unique code for each user, WhatsApp uses the same encryption code for everyone. This spells bad news for users since, in theory, a developer can make an app that can decrypt and gain access to that data. So long as you grant the app the permissions it asks for, your messages will be exposed in all their glory and possibly uploaded to third-parties.

Bosschert tested the theory by developing a companion app, and used a loading screen while the app acquired the database files and uploaded them. Unfortunately, the app succeeded in doing so, with Bosschert reporting that, even with yesterday’s WhatsApp for Android update, the security flaw still exists.

For reference, the iOS version of the app does the same thing, but Apple prevents access to the sandbox WhatsApp creates when storing data.

We have no idea when or if a fix is coming. Until then, chat casual.

Editors' Recommendations

Williams Pelegrin
Former Digital Trends Contributor
Williams is an avid New York Yankees fan, speaks Spanish, resides in Colorado, and has an affinity for Frosted Flakes. Send…
How to use WhatsApp Web
WhatsApp messaging app

As one of the most popular messaging services on the planet, there's a good chance you've already heard of WhatsApp. From its humble beginnings in 2009 — two years before Apple introduced iMessage — to its acquisition by Facebook (now Meta) in 2014, WhatsApp has become the dominant messaging platform around the globe. In recent years, it's grown even strong with the addition of new features like video messages, self-destructing voice messages, the ability to edit sent messages, and more.

As popular as the WhatsApp mobile apps are for iPhone and Android, it's easy to forget that you can also use WhatsApp on a desktop or laptop computer. The comapny provides native apps for Macs and Windows PCs, plus a web-based version that works in any modern web browser on nearly any platform.

Read more
WhatsApp now lets you send self-destructing voice messages
WhatsApp logo on a phone.

If you’re on WhatsApp and regularly make use of the view once feature for photo and video messages, then you might be interested to learn that the feature has now been expanded to voice messages.

WhatsApp’s view once feature does what it says, deleting a message after it’s been viewed a single time. It’s been available for photos and videos since 2021, but now you can also send voice messages that can only be played once before they, too, disappear from the app.

Read more
WhatsApp used to be one of my favorite apps. Now, I can’t stand it
WhatsApp logo on a phone held in hand.

For the best part of the last decade, WhatsApp has been my primary means to stay in touch with friends, family, peers at work, and even strangers. Texting is not as prevalent in my country, India, as it is in the U.S. for reasons such as the sheer dominance of Android users (as well as the diminutive share of iOS, and therefore, iMessage users), capped carrier costs for SMS-based messaging, and the poor understanding of RCS.

WhatsApp, on the other hand, is more widely used here than any other communication medium, primarily because it's free and allows the exchange of a multitude of types of media without being limited by national borders. People of all ages use and love it -- and they collectively send enough messages to clog up the internet.

Read more