Moneycontrol PRO
Loans
Loans
HomeTechnologyExperts raises concerns over WhatsApp’s end-to-end chat encryption; claims full recovery of encrypted chats possible using…

Experts raises concerns over WhatsApp’s end-to-end chat encryption; claims full recovery of encrypted chats possible using…

A recent forensic demonstration reveals that WhatsApp’s end-to-end encryption safeguards messages only during transit, while chats stored on unlocked devices can still be fully extracted, including deleted messages and media attachments.

December 01, 2025 / 17:05 IST
whatsapp

A new digital forensics demonstration shared by cybersecurity expert Nana Sei Anyemedu highlights an important distinction in how WhatsApp’s end-to-end encryption works. While the platform protects messages during transmission, the recovered data shows that once content reaches a device, it is no longer shielded by encryption. This gap allows forensic tools to extract complete chat histories from unlocked or lawfully accessed smartphones.

Stored chats remain accessible on unlocked devices

The demonstration, conducted on an iPhone 16 Pro running iOS 26.1, confirms that WhatsApp stores messages and media inside local databases on the device. These include files such as msgstore.db and other SQLite database formats that retain the complete messaging timeline.

Once a device is unlocked, decrypted, or accessed using forensic tools such as Cellebrite or Oxygen, investigators can read these databases in full. The extracted information can include:

Full message timelines

Timestamps and participant details

Photos, videos, voice notes, and document attachments

Potentially recoverable deleted messages

Despite the familiar banner that reads “Messages are now secured with end-to-end encryption” at the top of every WhatsApp chat, the encryption applies only to data moving between devices—not data stored on them.

End-to-end encryption protects data in transit, not at rest

End-to-end encryption ensures that WhatsApp servers cannot intercept or read messages during transmission. Encryption keys remain solely on users’ devices. However, once a message reaches the device, it is stored locally in unencrypted form inside WhatsApp’s directories.

Forensics practitioners rely on device-level access rather than intercepting network communication. If investigators obtain lawful access—through a passcode, biometric unlock, or device backup—they can extract the full contents of WhatsApp chats without breaking the encryption protocol itself.

Why this matters for users

The findings serve as a reminder that device security plays a crucial role in messaging privacy. While WhatsApp protects communication from external interception, users must still manage risks linked to physical device access, weak passcodes, unencrypted backups, or malware.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

first published: Dec 1, 2025 05:05 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347