Why WhatsApp Faces Persistent Criticism Over Security and Privacy – and How AI Technologies Are Reshaping the Debate

The view that WhatsApp suffers from serious security and privacy shortcomings is shared by many independent cybersecurity experts and has been vigorously promoted by Telegram founder Pavel Durov.

By 2026, his critiques had sharpened further: he declared that “you’d have to be braindead to believe WhatsApp is secure in 2026” after analyzing its encryption implementation and identifying multiple attack vectors, and later called its end-to-end encryption claims “the biggest consumer fraud in history,” largely because most messages end up in unencrypted cloud backups.
The criticism rests on several core technical and architectural factors that remain relevant today.
1. The Cloud Backup Problem

By default, chat histories are uploaded to cloud storage (Google Drive or iCloud) without end-to-end encryption — or without sufficiently robust keys enabled by default. Users must manually activate end-to-end encrypted backups (via a passkey, password, or 64-digit key).
Durov and others have long emphasized that the vast majority of users never do so. As a result, the conversations of hundreds of millions of people sit in plaintext or weakly protected form on servers belonging to major American corporations, where they can be accessed by third parties or law enforcement upon request. Even if one user enables encrypted backups, messages remain exposed if the other parties in the chat have not.
2. Closed-Source Code

3. Recurring Vulnerabilities and a History of Exploits
Over the years, critical flaws have repeatedly surfaced. Notable examples include vulnerabilities that allowed remote installation of commercial spyware (such as the Pegasus suite) simply via an incoming WhatsApp call. Critics point to the regular discovery of serious bugs as evidence that undermines confidence in Meta’s overall infrastructure reliability. Recent years have continued this pattern, with Google’s Project Zero disclosing significant issues and Meta issuing fixes under public pressure.
Specific Risks of WhatsApp Web

- It runs directly in the user’s browser, with executable code dynamically loaded from Meta’s servers. In theory, this architecture allows Meta — or an attacker who compromises the infrastructure — to silently modify the web client code for a specific user and intercept data at the moment of decryption in the browser.
- Multi-device synchronization requires the transmission of keys through Meta’s cloud servers, expanding the attack surface.
- Ordinary users have virtually no practical way to verify the authenticity and safety of the code currently executing in their browser.
Massive Metadata Collection
Even when message content itself is encrypted, WhatsApp gathers an enormous volume of metadata: who communicates with whom, when, and for how long; real IP addresses; location data; device characteristics; and the entire smartphone address book (including contacts of people who do not use WhatsApp). Meta uses this information for advertising and analytics purposes—practices that sit uneasily with any claim of absolute privacy.
The Growing Influence of AI Technologies
Artificial intelligence has both intensified existing concerns and introduced new dimensions to the debate.
On the defensive side, Meta deploys advanced AI models to detect non-human behavior, automated spam, and scams at scale. In 2025–2026 the company tightened risk controls with machine-learning systems that identify suspicious patterns more precisely than before, and it has partnered with AI firms such as OpenAI to disrupt scam operations that used generative tools to craft phishing messages targeting WhatsApp users. New “Strict Account Settings” further limit exposure for high-risk users by blocking media from unknowns, silencing certain calls, and restricting profile visibility.

This architecture uses trusted execution environments on specialized hardware, aims to process data with minimal retention, and is designed so that neither Meta nor third parties can read the content. Users can opt in, and an “Advanced Chat Privacy” setting lets participants block AI processing of specific chats. Meta asserts that personal messages remain end-to-end encrypted and that only messages explicitly directed at Meta AI (or deliberately shared) are visible to the AI service.
Independent experts, however, remain cautious. Cryptographers note that any off-device AI inference necessarily sends private data to cloud servers, creating a larger and more attractive target for sophisticated attackers or nation-state actors than a purely on-device or pure end-to-end system. The processing machines themselves become high-value assets. Critics also warn of a “slippery slope”: once cloud-based AI processing is accepted for convenience features, pressure may grow to expand its scope.
Meanwhile, AI amplifies offensive threats. Scammers increasingly use large language models to generate convincing phishing lures that arrive via WhatsApp, then pivot victims to other platforms. The same powerful analytics that Meta applies to metadata can, in principle, be leveraged by anyone with access to that data for deeper behavioral profiling.
Conclusion

In everyday use, however, closed-source code, optional (and rarely enabled) encrypted backups, web-client architecture, expansive metadata collection, recurring vulnerabilities, and the new attack surfaces introduced by cloud AI processing combine to create meaningful risks to user confidentiality.
As AI capabilities continue to expand both inside Meta’s systems and in the hands of adversaries, these long-standing architectural choices matter more than ever. Users who prioritize privacy are left weighing convenience against the practical limitations that independent experts and high-profile critics such as Durov continue to highlight.
Also worth reading:
---
- Comparing the Samsung Galaxy S26 Family and Apple iPhone 17 Pro — and Looking Ahead to 2027
- Weather Modification in the Age of AI: Half a Century of Technology in the Race for National Supremacy
- How to Verify and Optimize YouTube Channel Settings for Monetization in 2026
- GenYouTube (gen यूट्यूब): Why YouTube Dominates India and What Lies Ahead
- What Counts as Health Privacy for Remote Workers
---
Thank you!
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.