A newly discovered security flaw in WhatsApp Web allows technically proficient attackers to bypass the platform’s “View Once” privacy feature and successfully extract encrypted media files, according to researchers at Zengo X Research. The vulnerability, first uncovered during development work on the Zengo digital wallet platform, exposes a significant gap in how desktop clients handle disappearing photos and videos.
The Zengo X Research Discovery
How the Desktop Exploit Works
When users send media using the “View Once” setting, WhatsApp intends for the file to be viewed a single time before locking out screenshots and blocking subsequent access. However, according to Zengo X Research, attackers targeting the web client can extract the target file’s URL directly from the underlying source code of WhatsApp Web. Once the URL is secured, the user can download the image in its native encrypted format—saved with a .enc extension—and subsequently decrypt it using specialized tools such as OpenSSL and mediaKey.
Meta Acknowledges the Security Gap
Meta, the parent company of WhatsApp, acknowledged the security gap after researchers reported the issue. According to statements given to TechCrunch by company spokesperson Zade Alsawah, Meta is actively developing a software patch to resolve the vulnerability. “We recommend that users only send view-once messages to trusted individuals,” Alsawah said, noting the current risk inherent in utilizing the feature across desktop web browsers.
Upcoming Patch and Industry Debate
Meta plans to deploy an updated security patch to fix the loophole in the near future. Despite the forthcoming fix, the discovery has reignited industry debate regarding the technical reliability of privacy features built into cross-platform messaging ecosystems, particularly when those applications extend functionality to desktop web browsers.
Risks to Sensitive Personal Media
Security analysts warn that the vulnerability places intimate photos and sensitive personal media at risk of unauthorized downloading and redistribution. While the exploit requires specific technical steps rather than a simple click, the existence of the flaw demonstrates that client-side restrictions on desktop browsers can sometimes be bypassed.
Interim Guidance for Users
Pending the release of Meta’s official patch, security specialists advise users to avoid transmitting sensitive photographs or videos through WhatsApp Web’s “View Once” feature. Individuals seeking to protect personal data are encouraged to exercise caution with digital media sharing and to audit their account privacy settings regularly.

Worth a look