Source · Tier B · Documentation

Meta WhatsApp Private Processing (security review)

Trail of Bits. 2025. Trail of Bits publications library.

Originalhttps://trailofbits.com/library/meta-whatsapp-private-processing/
VersionLibrary entry for the review dated August 2025. The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf) could not be read by the fetch tool on 2026-09-25; the library entry gives the finding titles and severities.
Accessed2026-09-25
NoteIndependent auditors' summary of their review of WhatsApp Private Processing. Lists 28 issues (8 high, 4 medium, 4 low, 12 informational). The eight high-severity findings include attestation without freshness, the SEV-SNP TCB version not checked against the VCEK certificate, SEV-SNP attestation not bound to Meta-specific machines, CVMs compromised through environment-variable injection, ACPI SSDT injection by a malicious hypervisor, CVM images that cannot be reproduced, and GPU-hosted models that do not verify NVIDIA GPU attestation. The client is not named on the page.

Cited by

Search

Full search page