Source · Tier B · DocumentationSource · Meta WhatsApp Private Processing (security review)
Meta WhatsApp Private Processing (security review)
Trail of Bits. 2025. Trail of Bits publications library.
| Original | https://trailofbits.com/library/meta-whatsapp-private-processing/ |
|---|---|
| Version | Library entry for the review dated August 2025. The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf) could not be read by the fetch tool on 2026-09-25; the library entry gives the finding titles and severities. |
| Accessed | 2026-09-25 |
| Note | Independent auditors' summary of their review of WhatsApp Private Processing. Lists 28 issues (8 high, 4 medium, 4 low, 12 informational). The eight high-severity findings include attestation without freshness, the SEV-SNP TCB version not checked against the VCEK certificate, SEV-SNP attestation not bound to Meta-specific machines, CVMs compromised through environment-variable injection, ACPI SSDT injection by a malicious hypervisor, CVM images that cannot be reproduced, and GPU-hosted models that do not verify NVIDIA GPU attestation. The client is not named on the page. |