According to the source, a team of security researchers from the University of Vienna, led by Max Guenther, discovered a basic vulnerability in the WhatsApp and Signal messaging software that allows precise tracking of a user’s location down to their phone number. PCMag.
Image source: Signal/PCMag
After you send a message, a checkmark icon will appear next to the message in Messenger. In WhatsApp and Signal, one checkmark indicates that the message has reached the server, and a second checkmark appears when the message reaches the recipient’s device. The vulnerability exists in the tiny RTT (round trip time) interval.
Unlike read receipts, which are only triggered when you manually open a message, delivery notifications are automatically sent even if the incoming message goes directly to your spam folder. Based on the return time of this signal, an attacker can obtain a wealth of information about the user’s device, its usage characteristics and location.
Gunter says all you need is a phone number. To carry out the attack, no special equipment or inside knowledge is required – a simple script is enough to analyze RTT changes; similar tools are publicly available on platforms such as GitHub.
Image source: Guberm/PCMag
Researchers say even small fluctuations in transmission time carry important messages: “We receive a response from the target and can measure the time interval. We measure the notification return time: for example, it is shorter when the device is unlocked or in use compared to idle mode or simply locked.”
By analyzing the RTT, an attacker can determine how actively the owner is using the smartphone, estimate its approximate location and identify the landline network. For example, a work smartphone connected to office Wi-Fi exhibits more consistent RTT performance than a personal smartphone switching between cell towers, providing attackers with a tool for constant surveillance.
To report identified vulnerabilities, Meta✴ A $7,000 reward was paid to the developer, and Signal, as a non-profit organization, was unable to provide any compensation.
“The problem is that these vulnerabilities cannot be completely eliminated,” – Gunther said. PCMag points out that all messaging platforms have delivery notifications, so it’s unlikely that this issue will be completely resolved anytime soon.
Yuan✴ Signal took precautions, specifically they implemented rate limiting and reduced the intensity of message reception to stop some spam. However, this solution only slows down the attack.
If you find an error, select it with your mouse and press CTRL+ENTER.










