Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information

Security researchers have identified a significant privacy vulnerability termed "Careless Whisper," impacting messaging platforms such as WhatsApp and Signal. This flaw enables attackers to monitor user activity via silent delivery receipts without…

Security researchers have identified a significant privacy vulnerability termed "Careless Whisper," impacting messaging platforms such as WhatsApp and Signal. This flaw enables attackers to monitor user activity via silent delivery receipts without alerting the users or requiring prior contact.

Attackers can exploit this vulnerability by sending inconspicuous messages, such as reactions to non-existent content or expired edits. These actions trigger round-trip time (RTT) responses that reveal device states, which can be exploited using just a phone number.

The vulnerability affects over three billion WhatsApp users and millions of Signal users. It allows for continuous tracking of user activity and can also lead to battery drain on the affected devices.

Attackers can initiate invisible actions, such as self-reactions, reaction removals, or invalid deletions, prompting individual delivery receipts from each target device. This occurs even without ongoing communication between the attacker and the victim.

The delivery receipts reveal RTT variations: approximately one second for devices with screens on, two seconds when the screen is off, and 300 milliseconds when the app is running in the foreground on iPhones.

On WhatsApp, high-frequency pings, potentially up to sub-second intervals, enhance precision without sending notifications, unlike previous methods which were limited by alerts.

In multi-device configurations, the leakage is exacerbated as companion clients (web, desktop) respond separately. This makes it challenging to detect online status changes, such as desktop boot-ups indicating presence in an office.

This flaw enables attackers to monitor user activity via silent delivery receipts without alerting the users or requiring prior contact.
Noah Kensington · Thehackingpost

Real-world testing demonstrated that researchers could track a Xiaomi phone's network switches, calls, and laptop synchronizations across different networks.

Messenger Stealthy from Stranger Multi-Device Probing Threema Comparison

WhatsApp Yes Independent receipts Restrictive, single receipt

Signal Yes Independent receipts No probing from strangers

Threema No Synchronized receipts N/A

Advertisement

RTT patterns allow the fingerprinting of operating systems through receipt ordering, which varies between platforms such as Android, iOS, and macOS. Additionally, jitter can differentiate between chipsets like Qualcomm and Exynos.

Attackers can infer user schedules, screen time, or app usage, escalating from country-level geolocation in previous work to second-level behavior analysis.

Offensively, oversized reactions (1MB payloads) can result in data traffic of 3.7MB/second, silently inflating data bills or draining batteries by 14-18% per hour on iPhones and Samsung devices. Currently, there are no rate limits to curb these sustained attacks.

As of Sep 2024, Meta has acknowledged the issue but no patch has been released after 14 months. Signal has not responded to the findings.

Researchers recommend limiting delivery receipts to known contacts, adding RTT noise, validating message IDs on the client side, and implementing server-side rate limits. Users can also adjust privacy settings to limit messages from unknown contacts as a temporary measure.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories