In jargon it is called Bug bounty program. The Operation is simple: companies that deal with digital services put a bounty layout for those who find bugs in the code. The bigger the company, the more the risk increases, and the more generous the bounties are. Last October Apple announced that it is willing to pay too 2 million dollars for those who find the most critical bugs. In the 2016 the program was started with bounties from $200,000.
In the last few hours, the US version of Wired has reported a bug found within these programs which has put practically all software at risk. phone numbers saved on WhatsApp. A simple trick, which, however, replicated in a procedural way can allow you to download almost all telephone numbers saved on the app.
The discovery of a team of researchers
The flaw was discovered by a group of researchers from the University of Vienna. If you want to check the technical details you can find all the documentation on the GitHub portal. In short, on WhatsApp it is possible to know if a contact is registered on the platform. Not only that. Often it is also possible to immediately see the profile photo, the noname chosen for WhatsApp and bio.
WhatsApp has a new feature to protect you from online scams: how to use it
A normal user completes this operation with the numbers he has in his address book or in any case with those he has saved and then sends a message. Researchers have discovered that there is no limit to number of requests that can be made. The conclusion is simple. By trying every possible telephone number in the world they managed to reconstruct a archive with 3.5 billion telephone numbers registered on WhatsApp. To be precise: 3,456,622,387.
In the paper the researchers write that if this flaw had been found by criminals it would have become the “largest data leak in history”. Not only that. In addition to the telephone number, the researchers also recovered in many cases the profile photo and a short biography. Specifically, of the entire dataset they managed to enter a profile photo in the 57% of cases and a a bio in the 29% of cases.
WhatsApp’s response
Let’s make it clear. The news of this flaw was released only after that Meta has fixed the bug. Not only that. Also according to Meta there are no traces of attacks on the app based on this vulnerability. Here is the position of a Meta spokesperson reported by the 9To5Mac blog: “We are grateful to researchers at the University of Vienna for their collaboration and diligence within our Bug Bounty program. This collaboration has successfully identified a new enumeration technique that has exceeded expected limitations, allowing researchers to extract publicly available basic information.”

