A significant vulnerability was discovered in WhatsApp’s “View Once” feature, allowing attackers to bypass its privacy protections. The feature, designed to let users send media that can only be viewed once, was found to be easily exploited through modified WhatsApp Web clients. This vulnerability raised concerns about the effectiveness of privacy measures and the trade-offs involved.
Meta has since implemented a robust server-side fix that effectively blocks unauthorized access to “View Once” media on web clients. The updated solution prevents WhatsApp Web from receiving encrypted media for “View Once” messages altogether. This fix addresses the vulnerability and enhances the privacy protections of the “View Once” feature. The incident highlights the importance of ongoing security research and responsible disclosure to identify and address vulnerabilities.