Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers
2024/11/17 by Gabriel K. Gegenhuber, Gegenhuber, Gabriel K., Maximilian Günther +12 · 15 voices · 2 citations
Computer Science · #Advanced Malware Detection Techniques #Network Security and Intrusion Detection #User Authentication and Security Systems #cs.CR #cs.NI
paper · pdf · doi:10.48550/arxiv.2411.11194
openalex publication_date 2024/11/17 · openalex created_date 2024/11/21 · openalex updated_date 2026/07/28
Abstract
With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue.
Cited by
Discussions
- Exploiting silent delivery receipts to monitor users on instant messengers [hn, 20 points, 4 comments]
- Careless Whisper appears to have been an issue (at least) for @signal.org and Whatsapp for over a year now. 🧪🤖 arxiv.org/abs/2411.11194 [bsky, 6 points, 0 comments]
- Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users [hn, 5 points, 0 comments]
- Exploiting Silent Delivery Receipts to Monitor Mobile Instant Messengers [hn, 3 points, 0 comments]
- Tracking Phone Numbers via WhatsApp and Signal: Open-Source PoC [hn, 3 points, 0 comments]
- Last release whitepaper of the research "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers" (Whatsapp, Signal, ..) Defcon 33 arxiv.org/pdf/2411.11194 [bsky, 2 points, 0 comments]
- How (almost) any phone number can be tracked via WhatsApp & Signal – open-source PoC [bsky, 1 points, 0 comments]
- Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers #Hacking arxiv.org/abs/2411.11194 [bsky, 1 points, 0 comments]
- How any phone number can be tracked via WhatsApp & Signal open-source PoC arxiv.org/abs/2411.11194 That is why you should use #threema #infosec #cybersecurity #ethicalhacking #news #privacy [bsky, 1 points, 0 comments]
- Felt pretty.. might delete later… #security #mobile #secops #hacks arxiv.org/pdf/2411.11194 [bsky, 1 points, 0 comments]
- Exploiting silent delivery receipts to monitor users on instant messengers https:// arxiv.org/abs/2411.11194 # arxiv [mastodon, 0 points, 0 comments]
- That's great, though I wonder if there's any news about this yet? Kinda don't wanna have to install Threema again arxiv.org/abs/2411.11194 [bsky, 0 points, 1 comments]
- How (almost) any phone number can be tracked via WhatsApp & Signal – open-source PoC [bsky, 0 points, 0 comments]
- Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers "We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged [bsky, 0 points, 0 comments]
- "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers": https://arxiv.org/abs/2411.11194 [bsky, 0 points, 0 comments]
Related