19/01/2026
Careless Whisper: Exploiting Silent Delivery Receipts for IM Monitoring
The research paper identifies a critical privacy vulnerability dubbed Careless Whisper, which exploits silent delivery receipts in popular instant messengers like WhatsApp and Signal. By sending specifically crafted, non-notifying messages, an attacker can monitor a user’s real-time activity, including screen status, application usage, and daily routines, without their knowledge. This side-channel attack is accessible to "spooky strangers" who only possess a victim's phone number, bypassing traditional contact list protections. Furthermore, the researchers demonstrate that this technique can be used for resource exhaustion, such as covertly draining a device's battery or data allowance. The study concludes that the current multi-device architecture and lack of client-side validation necessitate urgent design changes to protect global users.