Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information
Security researchers have identified a significant privacy vulnerability termed "Careless Whisper," impacting messaging platforms such as WhatsApp and Signal. This flaw enables attackers to monitor user activity via silent delivery receipts without…
Security researchers have identified a significant privacy vulnerability termed "Careless Whisper," impacting messaging platforms such as WhatsApp and Signal. This flaw enables attackers to monitor user activity via silent delivery receipts without alerting the users or requiring prior contact.
Attackers can exploit this vulnerability by sending inconspicuous messages, such as reactions to non-existent content or expired edits. These actions trigger round-trip time (RTT) responses that reveal device states, which can be exploited using just a phone number.
The vulnerability affects over three billion WhatsApp users and millions of Signal users. It allows for continuous tracking of user activity and can also lead to battery drain on the affected devices.
Attackers can initiate invisible actions, such as self-reactions, reaction removals, or invalid deletions, prompting individual delivery receipts from each target device. This occurs even without ongoing communication between the attacker and the victim.
The delivery receipts reveal RTT variations: approximately one second for devices with screens on, two seconds when the screen is off, and 300 milliseconds when the app is running in the foreground on iPhones.
On WhatsApp, high-frequency pings, potentially up to sub-second intervals, enhance precision without sending notifications, unlike previous methods which were limited by alerts.
In multi-device configurations, the leakage is exacerbated as companion clients (web, desktop) respond separately. This makes it challenging to detect online status changes, such as desktop boot-ups indicating presence in an office.
This flaw enables attackers to monitor user activity via silent delivery receipts without alerting the users or requiring prior contact.
Real-world testing demonstrated that researchers could track a Xiaomi phone's network switches, calls, and laptop synchronizations across different networks.
Messenger Stealthy from Stranger Multi-Device Probing Threema Comparison
WhatsApp Yes Independent receipts Restrictive, single receipt
Signal Yes Independent receipts No probing from strangers
Threema No Synchronized receipts N/A
RTT patterns allow the fingerprinting of operating systems through receipt ordering, which varies between platforms such as Android, iOS, and macOS. Additionally, jitter can differentiate between chipsets like Qualcomm and Exynos.
Attackers can infer user schedules, screen time, or app usage, escalating from country-level geolocation in previous work to second-level behavior analysis.
Offensively, oversized reactions (1MB payloads) can result in data traffic of 3.7MB/second, silently inflating data bills or draining batteries by 14-18% per hour on iPhones and Samsung devices. Currently, there are no rate limits to curb these sustained attacks.
As of Sep 2024, Meta has acknowledged the issue but no patch has been released after 14 months. Signal has not responded to the findings.
Researchers recommend limiting delivery receipts to known contacts, adding RTT noise, validating message IDs on the client side, and implementing server-side rate limits. Users can also adjust privacy settings to limit messages from unknown contacts as a temporary measure.
Based on reporting by Cyber Security News.
