Best Cybersecurity News

WhatsApp View Once Vulnerability Let Attackers Bypass The Privacy Feature

Meta’s WhatsApp recently faced scrutiny after a significant vulnerability in its “View Once” feature was discovered, allowing attackers to bypass its privacy protections.

This feature, designed to let users send media that can only be viewed once, was found to be easily exploited through modified WhatsApp Web clients.

Although Meta has now implemented fixes, the issue has raised concerns about the effectiveness of privacy measures and the trade-offs involved.

WhatsApp View Once Vulnerability

The “View Once” feature is intended to enhance privacy by preventing recipients from forwarding, sharing, or copying sensitive media.

However, according to researcher Tal Be’ery, the protection could be bypassed using browser extensions that slightly modify WhatsApp’s web.

These extensions ignored the “View Once” flag attached to the media and enabled recipients to save or redistribute it.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

The core of the issue lay in how WhatsApp Web handled such media. Even though “View Once” content was not supposed to appear on web clients, it was still sent to them with a marker indicating its status.

A modified client could simply disregard this flag and access the media without restrictions.

This vulnerability was responsibly disclosed to Meta earlier this year. However, reports emerged in September 2024 that publicly available browser extensions with thousands of users were exploiting the flaw. This prompted researchers to publicly disclose their findings to warn users.

Meta initially released a partial fix in mid-September 2024, addressing some aspects of the problem. However, attackers quickly adapted their tools, rendering the fix ineffective.

In mid-November 2024, Meta rolled out a more robust server-side fix that effectively blocked unauthorized access to “View Once” media on web clients, reads the report.

The updated solution prevents WhatsApp Web from receiving encrypted media for “View Once” messages altogether.

View once feature bypass apps

Instead, web clients receive an error message when attempting to access such content. This approach ensures that only authorized devices can display the media.

While the fix resolved the immediate vulnerability, it introduced new concerns about metadata exposure.

Although end-to-end encryption (E2EE) protects message content, metadata—such as sender and recipient IDs and message types—remains visible to WhatsApp servers.

This metadata could potentially be exploited under certain circumstances, raising questions about user privacy.

Additionally, the fix does not address vulnerabilities in modified mobile clients or potential forensic extraction of “View Once” media from other devices linked to a user’s account.

Experts suggest that a more comprehensive solution involving device integrity checks or digital rights management (DRM) may be necessary.

Meta’s response to the “View Once” vulnerability represents a significant improvement in protecting user privacy but highlights the challenges of balancing security and usability.

Users are advised to remain cautious when using sensitive features like “View Once,” as no system is entirely foolproof.

Investigate Real-World Malicious Links,Malware & Phishing Attacks With ANY.RUN - Try for Free

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago