Uncategorized

WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security

WhatsApp has released a new Android update through the Google Play Beta Program, bringing the version up to 2.26.7.8. The update reveals that WhatsApp is actively developing an optional account password feature designed to add another layer of security on top of the existing two-step verification (2FA) system.

WhatsApp already offers two-step verification as an optional security measure, which requires users to enter a secondary PIN after successfully registering their phone number.

Earlier, in the WhatsApp beta for Android 2.23.24.10 update, the platform also introduced the ability to protect accounts using a registered email address, allowing users to regain access quickly when unable to receive the 6-digit SMS verification code, such as when a SIM card is temporarily unavailable.

Building on these efforts, Wabetainfo observed that WhatsApp is now working on an account password feature, a third authentication credential that sits on top of the existing verification flow.

The goal is to maximize account security by making unauthorized access significantly more difficult, even in cases involving SIM swapping or compromised devices.

How the Account Password Works

The account password is an alphanumeric string, between 6 and 20 characters in length, that must include at least one letter and one number.

Once set, WhatsApp will evaluate the chosen password and indicate whether it is strong enough, guiding users toward more robust security choices. Importantly, users can update or remove their password at any time, giving them full flexibility and control over their security configuration.

WhatsApp Password Feature (Source: Wabetainfo)

The feature integrates into the login flow at the final step. If a user has set an account password but not two-step verification, WhatsApp will prompt for the password immediately after the 6-digit SMS code is entered.

If both 2FA and the account password are enabled, users must first enter the two-step verification PIN, then the account password, creating a three-factor barrier against unauthorized access.

This means that even if a malicious actor obtains both the SMS verification code and the 2FA PIN through techniques like SIM swapping, they would still be blocked without the account password.

Setting an account password remains entirely optional, allowing users to decide whether they want this additional protection. This mirrors WhatsApp’s approach with two-step verification, which is also opt-in, rather than mandatory.

The new password feature does not replace existing security mechanisms; instead, it strengthens them by adding a credential layer known only to the account owner.

The account password feature is currently in development, according to Wabetainfo, and has not yet been rolled out publicly. WhatsApp is still refining how passwords can best secure accounts against unauthorized access, and once testing is complete, the feature will be gradually rolled out to users.

With account takeover attacks, including SIM swapping and phishing, remaining a persistent threat, this feature represents a significant step in WhatsApp’s ongoing effort to harden account authentication and reduce the risk of unauthorized access across its more than two billion users worldwide.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago