#1 Middle East & Africa Trusted Cybersecurity News & Magazine |

28 C
Dubai
Sunday, June 1, 2025
HomeTopics 1Application SecurityWhatsApp Bug Exposes Flaw in ‘View Once’ Privacy Feature – Users Urged...

WhatsApp Bug Exposes Flaw in ‘View Once’ Privacy Feature – Users Urged to Be Cautious

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

WhatsApp, the world’s leading end-to-end encrypted messaging platform, is facing scrutiny following the discovery of a significant bug that undermines its “View Once” privacy feature. Introduced in 2021, this feature was designed to enhance user privacy by allowing pictures and videos to disappear after being viewed once. However, a newly uncovered vulnerability in WhatsApp’s web application enables malicious users to bypass this function and retain content that was intended to vanish after a single view.

Details of the Vulnerability

The “View Once” feature on WhatsApp was developed to work exclusively on mobile applications for Android and iOS, warning users who attempt to open “View Once” media on WhatsApp Web or Desktop that they need to switch to their mobile devices. Unfortunately, Tal Be’ery, a cybersecurity researcher and CTO of crypto wallet company Zengo, discovered a critical flaw in WhatsApp’s web app that allows any recipient to bypass the “View Once” restriction.

Be’ery, who has been delving into WhatsApp’s privacy vulnerabilities for several months, published a blog post on September 9, 2024, highlighting this flaw. According to Be’ery, the bug permits malicious users to view and save “View Once” media without triggering the intended privacy safeguards. During a live demonstration for TechCrunch, Be’ery successfully captured and saved a “View Once” picture sent to him via WhatsApp Web.

“The only thing worse than no privacy is a false sense of privacy,” Be’ery noted in his blog post. He expressed concerns that users are misled into believing their communication is secure when it isn’t. “WhatsApp’s ‘View Once’ is a blunt form of false privacy and should either be thoroughly fixed or abandoned,” he added.

Be’ery reported the bug to Meta, WhatsApp’s parent company, through its bug bounty platform on August 26, 2024. In response to TechCrunch’s inquiry, WhatsApp spokesperson Zade Alsawah acknowledged the issue and stated, “We are already in the process of rolling out updates to View Once on web. We continue to encourage users to only send View Once messages to people they know and trust.” However, the company has not provided a specific timeline for when the fix will be fully deployed.

It is worth noting that Be’ery is not the first to identify this loophole. TechCrunch has identified numerous browser extensions that make bypassing the “View Once” feature on WhatsApp Web trivially easy. There have also been active discussions on various social media platforms outlining methods to exploit this vulnerability, amplifying the potential risk.

10 Tips to Avoid Such Threats in the Future

  1. Use Trusted Devices Only: Always use WhatsApp on mobile devices to ensure “View Once” messages work as intended.
  2. Verify Recipients: Only send sensitive media to people you know and trust. Avoid sending “View Once” messages to unknown or unverified contacts.
  3. Be Aware of Privacy Limitations: Understand that even features meant for privacy can have vulnerabilities. Remain cautious with sensitive content.
  4. Update WhatsApp Regularly: Ensure you are using the latest version of WhatsApp on all your devices to get the most recent security patches and updates.
  5. Avoid Clicking on Suspicious Links: Never click on links from unknown sources, which could lead to browser extensions designed to bypass WhatsApp’s security.
  6. Disable WhatsApp Web if Not in Use: If you do not need to use WhatsApp on the web, consider disabling it to minimize the risk of potential exploits.
  7. Use Additional Encryption Tools: Consider using additional encryption tools or apps that provide higher privacy and security for extremely sensitive content.
  8. Stay Informed About Security Updates: Follow security news and updates from reputable sources like TechCrunch to stay informed about any newly discovered vulnerabilities.
  9. Participate in Security Awareness Programs: Regularly engage in cybersecurity training to learn about emerging threats and how to protect yourself online.
  10. Report Suspicious Activity: Immediately report any suspicious activities or potential security vulnerabilities to WhatsApp or relevant authorities.

Conclusion

The recent discovery of a vulnerability in WhatsApp’s “View Once” feature serves as a stark reminder of the limitations of digital privacy tools. While WhatsApp works on rolling out updates to address this issue, users must remain vigilant and cautious. As cyber threats evolve, so must our understanding of the potential risks associated with digital communication platforms. Staying informed, cautious, and proactive is key to maintaining personal privacy and security in today’s interconnected world.

Source: Techcrunch

Want to stay on top of cybersecurity news? Follow us on Facebook – X (Twitter) – Instagram – LinkedIn – for the latest threats, insights, and updates!

Ouaissou DEMBELE
Ouaissou DEMBELEhttp://cybercory.com
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here