WhatsApp: “single view” function suffers from a flaw that allows it to be bypassed
Introduced three years ago, the WhatsApp messaging app's “View Once” feature lets you send a voice message, photo, or video to a recipient who can only view it once. Afterward, the message is automatically deleted from the conversation. The feature also prevents screenshots of messages on both Android and iOS versions of WhatsApp. Unfortunately, all of this can be easily circumvented, making this privacy-focused tool unreliable and unsecure.
A major flaw that dates back
As cybersecurity researcher Tal Be'ery points out: “Messages are sent to all of the recipient's devices, including those that are not authorized to view them. Additionally, messages are not immediately deleted from WhatsApp's servers after downloading.“
So, a “Single View” message that arrives on the desktop or web version of WhatsApp can easily be screenshotted. In addition, these single messages behave like regular messages, but with a simple flag “View once“. So, malicious people who receive a single message can simply transform that flag false, thus allowing the message to be downloaded, shared or forwarded.
WhatsApp is a free and secure instant messaging service that allows you to keep in touch with all your friends or family, you can download and install it on all platforms.
- Downloads:
16529 - Release date:
09/09/2024 - Author :
WhatsApp - License:
Free License - Categories:
Communication
- Operating system:
Android, Online Service, Windows 10/11, iOS iPhone, macOS
The researcher also states: “The only thing worse than no privacy is a false sense of privacy in which users are led to believe that certain forms of communication are private, when in reality they are not. Currently, WhatsApp's single view is a crude form of false privacy and should either be completely fixed or abandoned.“
While the researcher's team is the first to report this flaw, it has been actively exploited for at least a year. Browser extensions even exist to simplify the process. To Bleeping Computer, Meta said that they are rolling out changes to the “Single View” feature on the web version of WhatsApp. It remains to be seen whether this will be enough, while Meta also specifies, not necessarily very reassuring: “We continue to encourage users to only send one-time messages to people they know and trust.“