Black Hat Asia 2026 | When 3.5 Billion Strangers Can Exploit Your WhatsApp Devices

Black Hat Asia 2026 | When 3.5 Billion Strangers Can Exploit Your WhatsApp Devices

Source: YouTube · Black Hat · published Aug 27, 2026 · 36:33

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This Black Hat talk by Tal Be'ery shows WhatsApp's E2EE shifts risk from server to client, enabling rogue-client attacks—device enumeration, silent-ping stalking, and OS fingerprinting—forming a complete kill chain for pinpointed malware delivery 0:52.

Key Takeaways:
• E2EE (2016) makes the server a "dumb pipe," shifting attacks to individual endpoints 3:32
• Uploaded public keys are implicit device identifiers; Sesame multi-device makes all 5 trackable 12:12
• A research tool enumerates devices and sends different messages to each, enabling per-device payload delivery 16:52
• "Silent pings" enable online-status stalking with no user control or penalty 19:34
• Clients respond differently to malformed messages (iOS acks deletes, web acks reject-call), enabling OS fingerprinting and precise exploit delivery 25:27
• Meta partially fixed issues and paid a bounty, but gaps remain (e.g., detecting OpenClaw/Baileys agents) 27:34
• Fixes proposed: lockdown mode, message requests, and replacing Sesame with an ambassador-style protocol 33:05

WhatsApp's 2016-era security architecture must evolve to match its 3+ billion-user scale; users have no self-service defense today 32:26.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

very happy to be here. We just saw a 20 minutes long demo of display settings hacking. Uh so I hope we'll be fine. I don't know this is a computer I haven't used. So I hope everything will go well. So what are we going Okay. Okay. So welcome to the talk. Your number is up. Hacking WhatsApp when 3.5 billion people can hack your WhatsApp. And my name is Talberry. I'm the CEO for Zango. We've just been acquired by it Toro and this is my 10th time as Blacket speaker and I'm very excited to reach that mark. So what are we going to talk about today? We'll talk a little bit about WhatsApp security. Just a brief intro then we will focus on a rogue client attacks because there are could be attacks against WhatsApp server but we will talk more about the client raw client attacking each other. Okay. …