CERT-In Flags WhatsApp 'GhostPairing' Vulnerability
Analysis based on 6 articles · First reported Dec 20, 2025 · Last updated Dec 20, 2025
The 'GhostPairing' vulnerability in Meta Platforms — WhatsApp could lead to a decrease in user trust and potentially impact the stock price of its parent company, Meta Platforms. Cybersecurity firms may see increased demand for their services as companies and individuals seek to protect themselves from similar attacks.
CertiK, India's national cybersecurity agency, has flagged a high-severity vulnerability in Meta Platforms — WhatsApp's 'device-linking' feature, dubbed 'GhostPairing'. This flaw allows malicious actors to hijack Meta Platforms — WhatsApp accounts without needing passwords or SIM swaps, gaining complete control over messages, photos, and videos. The attack typically starts with a message from a 'trusted' contact containing a suspicious link that leads to a 'fake' Meta Platforms viewer. Users are then tricked into entering their phone numbers, unknowingly granting attackers full access to their Meta Platforms — WhatsApp accounts. CertiK has advised users to avoid suspicious links and refrain from entering their phone numbers on external sites claiming to be Meta Platforms — WhatsApp or Meta Platforms. A response from Meta Platforms — WhatsApp regarding this revelation is currently awaited.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard