Skip to main content
  1. Home
  2. Social Media
  3. News

WhatsApp says Google no longer indexes Click to Chat users’ phone numbers

Phone numbers of WhatsApp users who chose to create public links to their accounts will no longer be listed on Google. WhatsApp confirmed to Digital Trends that Google has blocked the practice, and a simple query for “site:wa.me” now won’t return an endless list of links to WhatsApp users.

The move comes after India-based security researcher Athul Jayaram highlighted how executing an empty query for WhatsApp’s Click to Chat URL can get you access to thousands of phone numbers and direct links to launching a chat with them.

Recommended Videos

WhatsApp’s Click to Chat tool allows anyone to fire up a chat without having to save the other party’s number on their phone first. Instead, users can simply append the number to a special web address and click on it to begin chatting with the recipient on WhatsApp.

The feature was primarily employed by businesses, since they were able to place that public link on their website to let visitors and customers easily reach out to their WhatsApp’s support channel without going through the hassle of saving the number in their phonebooks.

Jayaram said he was able to message several strangers whose WhatsApp numbers he managed to acquire from the wa.me search. The Google listing didn’t reveal any other personal information, such as the user’s number or status. However, Jayaram could view the pictures and names of people who hadn’t made their data private through WhatsApp’s security options.

By appending the country’s code at the end of the URL, Jayaram could also restrict the results to a specific region that could potentially prove handy to spammers and cybercriminals.

Jayaram reported the leak to Facebook through the social media company’s Bug Bounty programs. WhatsApp, however, told Digital Trends that it didn’t qualify for a bounty since it merely contained a search engine index of URLs that WhatsApp users chose to make public.”

WhatsApp landed in a similar controversy earlier this year in February when a report discovered that anyone could look up private group links — that were shared or posted on a public channel — on Google and access their list of phone numbers and participants by joining them without verification.

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
X wants you to stay forever in its app with a new way to click links
You can checkout anytime you like, but you can never leave
Twitter app on the OnePlus 10T.

What happened: You know how when you click a link on X (Twitter), the webpage takes over your whole screen and you kind of forget what post you were even looking at? It's pretty annoying. Well, they're testing a new look on iOS that fixes this.

Instead of the post disappearing, it shrinks down and sticks to the bottom of your screen.

Read more
Meta is killing Messenger on desktop, here’s what you need to do
Windows support ends December 14, Mac gets 60 days. Turn on secure storage to keep your chats.
Meta Messenger

What’s happened? Meta is discontinuing its Messenger desktop apps for Windows and macOS. Both listings are gone from the Microsoft Store and the Mac App Store, and users are getting in-app notices with a clear timeline. The service itself stays live on the web.

On Windows, the desktop app stops working on December 14, 2025. A notification appears if you have it installed.

Read more
Use a passkey on X? Update it by November 10 or lose access
Hardware keys and passkeys must be re-enrolled, authenticator apps are not affected, says X.
Twitter logo in white stacked on top of a blue stylized background with the Twitter logo repeating in shades of blue.

What’s happened? X has issued a warning to users that it's moving logins to x.com and, as part of that, plans to phase out the twitter.com domain. Anyone using a hardware security key or a passkey needs to re-enroll by November 10 so the key is tied to x.com instead. X says this is not a security incident, and authenticator apps are unaffected.

The company’s Safety account said that accounts using security keys for 2FA must re-enroll to keep access, via posts on X.

Read more