HomeTechnologyWhatsApp users face new threat as CERT-In flags attack that can hijack accounts without OTP

WhatsApp users face new threat as CERT-In flags attack that can hijack accounts without OTP

CERT-In has warned WhatsApp users about a new attack that can hijack accounts without OTP by misusing the app’s device-linking feature.

December 20, 2025 / 21:28 IST
Story continues below Advertisement
whatsapp
whatsapp

It often starts with a message that feels completely normal. A quick “Hi, check this photo” from someone you know. Nothing suspicious, nothing urgent. Just another link in a WhatsApp chat. But according to India’s cyber security agency, that one click could be enough to quietly hand over control of your WhatsApp account to a cyber criminal.

India’s national cyber response body, CERT-In, has flagged a serious security issue in WhatsApp that attackers are already exploiting. The vulnerability, called “GhostPairing,” targets WhatsApp’s device-linking feature and allows criminals to access a user’s account without needing a password, an OTP, or even a SIM swap.

Story continues below Advertisement

The attack works by taking advantage of how people normally use WhatsApp Web. After clicking on the link, users are redirected to a fake website that looks like a familiar Facebook-style media viewer. To see the photo or video, the site asks users to “verify” themselves. During this step, victims are asked to enter their phone number, believing it is part of a routine check.

What users don’t realise is that this action allows attackers to secretly link their own browser to the victim’s WhatsApp account using a pairing code that looks legitimate. Once linked, the attacker’s device becomes a hidden, trusted device on WhatsApp Web.