Audio By Carbonatix
Some messages sent through WhatsApp can be intercepted and read thanks to a bug in the app, suggests research.
The bug arises because of the way WhatsApp encrypts the messages sent via its service.
Security expert Thomas Boelter found that eavesdropping was possible when circumstances called for encryption keys to be reissued.
Mr Boelter told WhatsApp owner Facebook about the issue in April 2016 but it said it was not working on a fix.
The response he received said that what he had discovered was expected behaviour.
Privacy campaigners claimed in The Guardian newspaper that the bug was a "huge threat" to freedom of speech because it could be used by governments or law enforcement agencies to spy on people who thought they were communicating securely.
In a statement reacting to media stories about the research, WhatsApp said the bug was not a "backdoor" intentionally placed in its code that allowed governments to make the firm decrypt messages.
"This claim is false," it said. "WhatsApp does not give governments a 'backdoor' into its systems and would fight any government request to create a backdoor."
Bad coding
The bug crops up in situations when encryption keys used to scramble messages have to be reissued and resent.
Mr Boelter found that, in certain circumstances, attackers can pose as the recipient of a message and force WhatsApp to reissue keys for scrambling information.
Sophisticated manipulation of this system would let attackers intercept and read messages, said Mr Boelter.
Zack Whittaker, security editor at ZDNet, said it was a "stupid and big bug" but played down its seriousness.
The problem was "limited" in its scope, he said, adding that it probably emerged because of "bad coding or a favour to good user experience".
In its statement, WhatsApp said it had taken a design decision to implement the re-issuing of keys in this way to preserve millions of messages that would otherwise be lost.
Cryptographer Frederic Jacobs said anyone worried about falling victim to the bug could adjust security settings on the app to warn them if encryption keys were being changed.
Latest Stories
-
2026 U-20 WWC: Black Princesses fall to Ecuador in opening game
1 hour -
GPL 2026/27: Hearts of Oak start new season with emphatic win over Berekum Chelsea
2 hours -
GPL 2026/27: Asante Kotoko held by debutants Debibi United in four-goal thriller
2 hours -
CAF CL: Medeama suffer home defeat in first leg against TP Mazembe
2 hours -
GPL 2026/27: Samartex secure 3-1 victory over Karela in season opener
3 hours -
Kumawu MP calls for urgent action on SHS infrastructure deficits
3 hours -
Vice President urges Methodist Church to add digital skills to women’s training programmes
4 hours -
Forestry Commission arrests 12 illegal miners in Atewa Forest
4 hours -
NPP National Treasurer aspirant involved in accident during campaign
5 hours -
Treat coastal communities as partners in sea turtle conservation – Dr Agyekumhene
5 hours -
The Chief Justice is not a Touring Minister: Baffoe-Bonnie’s SOE visits are unconstitutional officiousness
5 hours -
Enforcing environmental laws carries political cost, while offenders go unpunished – Frimpong-Boateng
5 hours -
Galamsey fight collapsed after safeguards introduced in 2018 were abandoned – Prof Frimpong-Boateng
5 hours -
Jail officials who approve projects in wetlands and forest reserves – Prof Frimpong-Boateng
6 hours -
Ghana needs $21bn to restore lands damaged by illegal mining – Frimpong-Boateng
6 hours