Score: 1

Prekey Pogo: Investigating Security and Privacy Issues in WhatsApp's Handshake Mechanism

Published: April 9, 2025 | arXiv ID: 2504.07323v2

By: Gabriel K. Gegenhuber , Philipp É. Frenzel , Maximilian Günther and more

Potential Business Impact:

Breaks WhatsApp's secret message protection.

Business Areas:
E-Signature Information Technology, Privacy and Security

WhatsApp, the world's largest messaging application, uses a version of the Signal protocol to provide end-to-end encryption (E2EE) with strong security guarantees, including Perfect Forward Secrecy (PFS). To ensure PFS right from the start of a new conversation -- even when the recipient is offline -- a stash of ephemeral (one-time) prekeys must be stored on a server. While the critical role of these one-time prekeys in achieving PFS has been outlined in the Signal specification, we are the first to demonstrate a targeted depletion attack against them on individual WhatsApp user devices. Our findings not only reveal an attack that can degrade PFS for certain messages, but also expose inherent privacy risks and serious availability implications arising from the refilling and distribution procedure essential for this security mechanism.


Page Count
19 pages

Category
Computer Science:
Cryptography and Security