WhatsApp 'View Once' messages are far more permanent than you realize

Researchers discovered a worrying vulnerability, then another...
By Matt Binder  on 
WhatsApp app
A WhatsApp exploit is allowing users access to View Once messages after they are supposed to be inaccessible. Credit: Silas Stein/picture alliance via Getty Images

If you're sending a "View Once" message, photo, or video through WhatsApp, don't be so sure that the receiver can't view it again.

Security researchers with crypto wallet ZenGo recently discovered a bug that allowed WhatsApp users to view "View Once" messages as many times as they liked.

In response, WhatsApp patched the issue. But, ZenGo researchers then discovered another exploit in WhatsApp's temporary fix that once again allowed them to access these messages that had supposedly disappeared.

WhatsApp View Once exploit

WhatsApp launched its View Once feature in 2021. View Once allows users to send texts, photos, and videos that disappear after the recipient initially accesses them. 

Furthermore, to ensure the ephemeral nature of these messages, WhatsApp disables screenshots from being used in the app on View Once messages through iOS and Android. In addition, WhatsApp limits View Once messages to the mobile apps only.

However, in a post last week, ZenGo Security Research Manager Tal Be'ery detailed an exploit that allowed his team to access View Once messages over and over again.

Basically, as Be'ery explains, the View Once messages are only restricted from view in the mobile apps after being viewed. The media continues to exist on WhatsApp's servers. If a user can find the URL for the media file, they can access the message or media file that was supposed to have disappeared.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Be’ery went through the official channels with WhatsApp's parent company Meta and reported the exploit through their bug bounty program on August 26. It was too late though. Be'ery soon found that the bug was already in the wild, as a Chrome extension popped up allowing users to access their already-viewed View Once messages through WhatsApp's web app. ZenGo went public with the exploit and published their report last week on Sept. 9.

Meta's fix and exploit #2

It appears the issue has been taken seriously by Meta, at least after Be’ery went public with the exploit. Meta appears to have released a fix for the WhasApp View Once bug on Sept. 12.

According to a new report by Be'ery, Meta's patch "changes the way View Once media messages are saved to the application’s databases and redact some of the information that enables the media viewing."

The fix appears to have broken the previously mentioned "View Once Photos Bypass" Chrome extension as well.

But, the fix is "still not enough," according to Be'ery and can be exploited with a workaround. In fact, as Be'ery discovered, the creator of the View Once bypass Chrome extension published an update saying that they've already discovered a new exploit in order to once again access View Once media.

Be'ery also published a video showing how View Once messages are still accessible.

Meta told Mashable that it's taking multiple steps to deal with the View Once issue. The initial fix was meant to be temporary as Meta restructures how View Once works in WhatsApp on the web.

"As we said before, we are in the process of rolling out multiple updates to View Once on web," a WhatsApp spokesperson told Mashable. "Those additional updates are forthcoming."

UPDATE: Sep. 18, 2024, 2:04 p.m. EDT This piece has been updated with a statement and additional information from Meta.


Recommended For You

WhatsApp video calls now have backgrounds and filters
WhatsApp video call filters

Hinge adds limit on unanswered messages
your turn limits on hinge

Meta updates WhatsApp and Messenger third-party chats in Europe
Close-up of using mobile phone on holographic background


Trending on Mashable
NYT Connections hints today: Clues, answers for December 6, 2024
A phone displaying the New York Times game 'Connections.'

Wordle today: Answer, hints for December 6
a phone displaying Wordle

NYT Mini crossword answers, hints for December 6, 2024
Closeup view of crossword puzzle clues

Tesla suspends Cybertruck production. Who could have predicted this?
Tesla vehicles, including Cybertrucks, loaded on a transport that seems to be going nowhere.

Wordle today: Answer, hints for December 5
a phone displaying Wordle
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!