Security News > 2020 > June > WhatsApp Phone Numbers Pop Up in Google Search Results — But is it a Bug?

WhatsApp Phone Numbers Pop Up in Google Search Results — But is it a Bug?
2020-06-05 16:01

UPDATE. A researcher is warning that a WhatsApp feature called "Click to Chat" puts users' mobile phone numbers at risk - by allowing Google Search to index them for anyone to find.

The phone numbers are revealed as part of a URL string and so, this in effect "Leaks" the mobile phone numbers of WhatsApp users in plaintext, according to the researcher's view.

Because WhatsApp identifies users by phone numbers, Google Search only revealed the phone numbers and not the identities of users that they were connected to, Jayaram explained.

The researcher said he was also able to see users' profile pictures on WhatsApp along with their phone numbers, merely by clicking on the Google Search phone number URLs, which brought him to their WhatsApp profiles.

The researcher maintains that many Click to Chat users are unaware that their phone numbers are being stored in plaintext, indexed by Google Search and discoverable via a relatively simple search query.


News URL

https://threatpost.com/whatsapp-phone-numbers-google-search-results/156141/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 256 4320 4678 741 9995
Whatsapp 5 1 11 13 16 41