International Edition
Latest News
Technology

WhatsApp Web Flaw Allows Users to Bypass “View Once” and Steal Private Photos

A newly discovered security flaw in WhatsApp Web allows technically proficient attackers to bypass the platform's "View Once" privacy feature and successfully extract encrypted media files, according to researchers at Zengo X Research. The vulnerability, first uncovered during…

A newly discovered security flaw in WhatsApp Web allows technically proficient attackers to bypass the platform’s “View Once” privacy feature and successfully extract encrypted media files, according to researchers at Zengo X Research. The vulnerability, first uncovered during development work on the Zengo digital wallet platform, exposes a significant gap in how desktop clients handle disappearing photos and videos.

The Zengo X Research Discovery

How the Desktop Exploit Works

When users send media using the “View Once” setting, WhatsApp intends for the file to be viewed a single time before locking out screenshots and blocking subsequent access. However, according to Zengo X Research, attackers targeting the web client can extract the target file’s URL directly from the underlying source code of WhatsApp Web. Once the URL is secured, the user can download the image in its native encrypted format—saved with a .enc extension—and subsequently decrypt it using specialized tools such as OpenSSL and mediaKey.

Meta Acknowledges the Security Gap

Meta, the parent company of WhatsApp, acknowledged the security gap after researchers reported the issue. According to statements given to TechCrunch by company spokesperson Zade Alsawah, Meta is actively developing a software patch to resolve the vulnerability. “We recommend that users only send view-once messages to trusted individuals,” Alsawah said, noting the current risk inherent in utilizing the feature across desktop web browsers.

Upcoming Patch and Industry Debate

Meta plans to deploy an updated security patch to fix the loophole in the near future. Despite the forthcoming fix, the discovery has reignited industry debate regarding the technical reliability of privacy features built into cross-platform messaging ecosystems, particularly when those applications extend functionality to desktop web browsers.

Risks to Sensitive Personal Media

Security analysts warn that the vulnerability places intimate photos and sensitive personal media at risk of unauthorized downloading and redistribution. While the exploit requires specific technical steps rather than a simple click, the existence of the flaw demonstrates that client-side restrictions on desktop browsers can sometimes be bypassed.

Interim Guidance for Users

Pending the release of Meta’s official patch, security specialists advise users to avoid transmitting sensitive photographs or videos through WhatsApp Web’s “View Once” feature. Individuals seeking to protect personal data are encouraged to exercise caution with digital media sharing and to audit their account privacy settings regularly.

Sus fotos íntimas en WhatsApp están en peligro, detectan falla en la plataforma
Photo: lafm.com.co
How to Open a View Once Photo on WhatsApp Web (2025 Updated)
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”