Updated 9 June 2020 at 19:03 IST
Your WhatsApp number could be available in Google Search results? Read here
Your WhatsApp number is at the risk of being leaked as a cybersecurity researcher has discovered a bug that allows users' numbers to show up on Google Search.
- Tech News
- 3 min read

A cybersecurity researcher named Athul Jayram has found a WhatsApp bug that prompts thousands of phone numbers to appear on Google search. The flaw in the WhatsApp web portal has affected users from countries like India, the US and the UK, among others. Athul has revealed that the bug is part of the appโs Click to Chat feature which puts a user's number on Google Search to be indexed.
What is WhatsApp โClick to Chatโ feature?
The โClick to Chatโ is a feature that allows users to initiate a WhatsApp conversation with another user without having to save their phone numbers in the phoneโs address book.
The feature was introduced two years ago and is especially convenient for business communication. It also allows websites to chat with their visitors where the visitors wouldnโt need to dial in the phone number. The process essentially works by creating QR codes or URL links for users that can be used by anyone to reach them using WhatsApp. Once the call is made, the visitor gets access to the personโs phone number.
Advertisement
Security concerns for WhatsApp users
The biggest flaw of the โClick to Chat featureโ is that Googleโs search engine also adds their phone number to Googleโs search index by indexing the featureโs metadata. According to Athul, who is a cybersecurity researcher, a userโs mobile number gets revealed as part of a URL string which goes on to leak the phone numbers for that particular WhatsApp user in a plaintext. However, the worst part is that it canโt be revoked.
Advertisement
The researcher also stated that the system actually makes it much easier for spammers to collect a userโs mobile number to spam them. He further added that over 3,00,000 phone numbers have been leaked on Google Search in plain text. What makes it all the more disturbing is that he was also able to view the profile pictures of WhatsApp users. This can actually make it easier for a hacker to perform a reverse search on an image on Google to track down the userโs location.
Athul discovered the bug on May 23 and contacted Facebook regarding the issue. The company responded that the issue does not qualify for a bug bounty as only Facebook platforms were part of the bounty program. Additionally, the company suggested that it isnโt that big a deal as users choose to make the information public.
Image credits: Allie Smith | Unsplash
Published By : Danish Ansari
Published On: 9 June 2020 at 19:03 IST