Cybersecurity experts discover a critical video calling flaw in WhatsApp that allows remote hackers to compromise mobile phones.
Cybersecurity researchers have uncovered a critical security flaw within WhatsApp’s video calling system that could allow internet hackers to take control of target smartphones remotely.
The serious technical vulnerability exists inside the app’s real-time video processing software, which handles incoming and outgoing video call data.
When an attacker sends a specially crafted, corrupted video call signal to a target phone number, the bad code causes an internal memory buffer overflow error.
This unexpected computer glitch freezes the application and allows remote intruders to bypass normal mobile security checks, access private chat records, and potentially execute harmful code on infected devices.
The critical mobile vulnerability warning was formally analyzed and shared across international cybersecurity networks on Wednesday, September 2, 2026.
Security researchers tracked how the technical flaw impacts millions of active mobile devices running both Android and Apple iOS operating systems.
Unlike traditional phishing schemes that rely on deceptive text links or tricking victims into downloading suspicious files, this video call flaw exposes devices to potential remote hijacking during the initial connection handshake phase before a user even decides to answer.
The primary reason this video calling bug is so dangerous is that it targets the underlying memory management system that processes live video streams.
Modern smartphones use complex computer code to convert incoming video data into clear images on screen. When an attacker deliberately sends corrupted data packages through an incoming video call request, the app attempts to read more data than its memory storage area can safely hold.
This memory overflow creates a temporary gap in device defenses, allowing remote criminals to overwrite system instructions, spy on personal files, or force the messaging application to crash completely.
Explaining how receiving a malformed video call package triggers severe memory errors inside mobile applications, Google Project Zero security researcher Natalie Silvanovich stated that “the vulnerability is a memory heap overflow issue which is triggered when a user receives a specially crafted malformed packet via a video call request”.
Detailing how memory processing errors can lead to unexpected app crashes and dangerous device exploitation, Natalie Silvanovich added that the flaw results in a “corruption error and crashing the WhatsApp mobile app,” opening up potential attack avenues for malicious hackers.
Emphasizing that company software engineers acted swiftly to patch the video calling code and protect users worldwide, WhatsApp security representatives confirmed in official technical advisories that new system protections were pushed to app stores to ensure that end-to-end user privacy remains fully protected against unauthorized intruders.
By uncovering and fixing the video calling flaw, cybersecurity researchers and developers are keeping mobile users safe. Updating messaging applications regularly and enabling automatic system patches ensures that smartphones stay protected, video calls remain private, and personal data stays locked away from internet thieves.

