Published: August 30, 2025
26
93
516

A week ago, I reported a privacy vulnerability to @Meta which may allow attackers to discover any @WhatsApp users' devices details, including online status and operating system. This flaw enables adversaries to accurately target a vulnerable iOS (iPhone) device.

@TalBeerySec @Meta @WhatsApp 🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥

@UK_Daniel_Card @Meta @WhatsApp Thanks man, I really appreciate your support

@mikebelshe @Meta @WhatsApp Thanks you for your support :)

@TalBeerySec @Meta @WhatsApp that's a really cool find!

@mbrg0 @Meta @WhatsApp Thanks mate. Coming from you it's a real compliment

@TalBeerySec @Meta @WhatsApp Have Meta acknowledged?

@yo_yo_yo_jbo @Meta @WhatsApp "A member of Meta’s security team has seen your report and performed an initial evaluation. We will get back to you once we have more information to share."

Image in tweet by Tal Be'ery

@TalBeerySec @Meta @WhatsApp Thanks for the awesome work man. You save the world !

@SaifuddinAmri__ @Meta @WhatsApp Thanks. Just trying to do my part.

@TalBeerySec @Meta @WhatsApp Nice work, friend! 💪

@rvrsh3ll @Meta @WhatsApp Thanks mate :)

@TalBeerySec @mbrg0 @Meta @WhatsApp יש דרך לחסום את זה?

@shakedko @mbrg0 @Meta @WhatsApp לא שאני מכיר. לחסום את המשתמש שסורק אותך עובד, אבל איך תדע מראש מי יסרוק אותך

@TalBeerySec How can normal user have access whatsapp web interface (eg: device management) console?

@__djazzy This screenshot/capture is of a tool I had created, not of WhatsApp web interface

@TalBeerySec @Meta @WhatsApp So.. have WhatsApp found any conclusive evidence that anybody was fingerprinted/attacked by this or just the vulns?

@JustWantToQ1 @Meta @WhatsApp We will probably never know for certain

@TalBeerySec @Meta @WhatsApp Nice work! Thank you!

@Cthulhu_Answers @Meta @WhatsApp power to the people

@TalBeerySec @Meta @WhatsApp Any specific reason to call privacy vulnerability and not security vulnerability? Or both same?

Image in tweet by Tal Be'ery

@TalBeerySec @cyb3rops @Meta @WhatsApp Is the online status visible regarding the users privacy settings?

@reni_ni @cyb3rops @Meta @WhatsApp As far as I can tell, there is no way for users to protect themselves with relevant privacy settings.

Share this thread

Read on Twitter

View original thread

Navigate thread

1/35