Call, Crash, Repeat: Hacking WhatsApp

Luke McLaren

REcon 2025 · Day 1 · Main Track

With roughly two billion active users worldwide, WhatsApp is the most widely deployed end-to-end encrypted messaging platform on Earth. Its ubiquity makes it both an attractive target for adversaries

AI review

Four real bugs in WhatsApp's VoIP stack — including a cross-platform crash primitive and a multi-step unauthorized camera access chain — from someone who actually understands the XMPP/PJSIP/WebRTC architecture rather than just fuzzing blind.

Watch on YouTube