Listen to this Post
A More Secure WhatsApp for More Than 2 Billion Users
WhatsApp is taking another major step toward making account takeovers, impersonation and scam calls harder for attackers. Meta has announced a new group of security improvements for WhatsApp, expanding passkey support, strengthening two-step verification and giving Android users more context when an unknown person calls.
These changes may look small individually, but together they address several of the most common ways criminals attempt to compromise messaging accounts. Instead of relying entirely on SMS codes or a simple six-digit PIN, WhatsApp is increasingly moving toward stronger authentication methods that are tied to a user’s device and protected by biometrics or a secure screen lock.
The timing is significant. Messaging accounts have become valuable targets because they can provide attackers with access to private conversations, contacts, groups and personal information. A compromised WhatsApp account can also become a powerful tool for social engineering, allowing criminals to impersonate the victim and target friends, relatives or colleagues.
Meta’s latest announcement therefore represents more than a collection of convenience features. It reflects a broader shift toward making account security easier for ordinary users while simultaneously making common attack techniques more difficult to execute.
WhatsApp Now Supports Multiple Passkeys
One of the most important updates is expanded passkey support. WhatsApp now allows users to have more than one passkey associated with the same account.
That is particularly useful for people who regularly move between devices or maintain both an iPhone and an Android phone. Previously, authentication could become less convenient when users changed devices or relied on multiple platforms.
With multiple passkeys, the security model becomes more flexible without forcing users to sacrifice strong authentication.
Passkeys Replace a Major Weak Point
Passkeys are designed to reduce dependence on passwords and SMS-based authentication. Instead of remembering a traditional password, users authenticate through the security system already built into their device.
Depending on the platform, that can mean Face ID, Touch ID or the device’s screen-lock mechanism.
This matters because passwords and one-time codes can be stolen through phishing. A criminal can trick someone into revealing a verification code, but stealing a cryptographic credential protected by the user’s device is considerably more difficult.
More Than One Billion Passkey Users
WhatsApp says more than 1 billion people now use passkeys to log back into their accounts with Face ID, Touch ID or a screen-lock code.
The company first introduced passkey support on Android in October 2023 before bringing the technology to iPhone users in April of the following year.
That adoption figure highlights how quickly passkeys have moved from an emerging authentication technology into a mainstream security mechanism.
For a platform with an enormous global user base, even incremental improvements can have a substantial security impact.
Stronger Two-Step Verification Arrives
WhatsApp is also upgrading its two-step verification system.
Previously, users could protect their accounts with a six-digit PIN. The new system expands that protection to full alphanumeric passwords, including special characters.
That is a meaningful improvement because a longer and more complex password can provide substantially more protection than a short numeric PIN, particularly when users choose a strong and unique password.
Why a Six-Digit PIN Was Not Enough
A six-digit PIN is convenient, but convenience can become a weakness when users reuse predictable numbers or choose information that is easy to guess.
A stronger password gives users more room to create credentials that are difficult to predict.
However, the effectiveness of the feature will still depend heavily on user behavior. A complex security option cannot provide maximum protection if someone chooses an obvious password or reuses the same credential across multiple services.
Two Layers Are Better Than One
WhatsApp describes two-step verification as an additional protection layer that can help prevent account takeover even if someone obtains the user’s one-time passcode.
That distinction is extremely important.
Attackers frequently attempt to obtain verification codes through social engineering. They may pretend to be a friend, customer-support representative or even the victim’s family member.
If an attacker obtains the one-time code but cannot overcome the additional verification layer, the account can remain protected.
Unknown Calls Get More Context on Android
The third major feature focuses on a different problem: suspicious calls.
WhatsApp is introducing additional information for calls from people who are not saved in a user’s contacts, although the feature is initially available on Android.
Instead of seeing only an unfamiliar number, users can receive additional context about the caller.
WhatsApp says this can include whether the number originates from another country and whether the caller shares any groups with the recipient.
More Information Can Stop a Scam Before It Starts
This is a simple idea with potentially significant consequences.
Scammers often rely on urgency. The goal is to get the victim to answer immediately, trust the caller and follow instructions before thinking carefully about what is happening.
Giving users more information before they answer creates an opportunity to pause.
A foreign number, an unfamiliar caller and no shared groups may not automatically mean the call is malicious, but the combination could encourage a user to be more cautious.
Social Engineering Remains the Bigger Threat
Technical security controls are important, but many successful attacks still depend on manipulating people.
An attacker does not necessarily need to exploit a sophisticated software vulnerability if they can convince someone to provide a verification code, click a malicious link or transfer money.
That makes contextual security features particularly interesting.
WhatsApp is not simply trying to prevent attacks at the technical layer. It is also attempting to give users better information at the exact moment when they need to make a security decision.
iPhone Users Already Have Similar Protection for Cellular Calls
The concept is not entirely new to smartphone users.
Apple offers Call Screening on supported iPhones running iOS 26, allowing unknown callers to be asked for their name and reason for calling before the phone rings.
However,
That distinction matters because messaging applications have effectively become communication networks of their own.
WhatsApp Is Becoming a Security Target
The enormous popularity of WhatsApp makes it an attractive target for criminals.
A stolen account can be used to send fraudulent messages to existing contacts, distribute phishing links, request emergency payments or attempt to compromise other accounts.
The attacker does not necessarily need to convince strangers that they are legitimate. They only need to compromise one account and then exploit the trust that already exists between the victim and their contacts.
Account Takeovers Can Spread Quickly
A compromised WhatsApp account can become the starting point for a much larger campaign.
Imagine an attacker gaining access to one
Some recipients may immediately trust the message because it appears to come from someone they already know.
This is why account security on messaging platforms has implications beyond the individual account owner.
Passkeys Make Phishing Harder
One of the strongest arguments for passkeys is their resistance to conventional phishing.
Traditional credentials can be typed into fake websites. Authentication codes can be manipulated through social engineering.
Passkeys work differently because the underlying cryptographic credentials are designed to authenticate with the legitimate service rather than simply handing a reusable secret to a website.
That does not make users completely immune to attacks, but it removes an important opportunity for criminals.
Convenience Is Becoming Part of Security
Historically, security often meant adding friction.
Long passwords, security questions, authentication codes and complicated recovery processes could make accounts safer but also frustrate ordinary users.
Passkeys attempt to reverse that relationship.
A fingerprint or face scan can be easier than remembering a password, while simultaneously providing stronger protection.
This is one reason passkeys are becoming increasingly important across the technology industry.
The Multi-Device Era Needs Multi-Passkey Security
Allowing multiple passkeys is particularly relevant as people increasingly use several devices.
A user might have an iPhone, an Android tablet, a second smartphone or another supported device.
Security systems built around a single authentication credential can become inconvenient when users switch between devices.
WhatsApp’s new approach acknowledges that modern users rarely operate from one device alone.
Security Should Follow the User
The best authentication system is not necessarily the one with the most complicated setup.
It is the one users can actually maintain.
If users abandon strong security because it becomes too difficult to manage, the theoretical protection becomes less useful.
Multiple passkeys could help address that problem by allowing users to retain secure authentication across their personal device ecosystem.
Attackers Are Also Becoming More Adaptive
Cybercriminals are not standing still.
As platforms improve authentication, attackers increasingly turn toward social engineering, phishing, SIM-related attacks, malware and other methods that target the person rather than the authentication technology.
That means
The new caller-context feature is an example of that broader approach.
Unknown Numbers Are a Psychological Weapon
An unexpected call creates pressure.
The victim may wonder whether it is an emergency, a business contact, a delivery service or someone they know using a new number.
Attackers can exploit that uncertainty.
Providing additional information about the caller gives users another signal before they decide whether to engage.
Shared Groups Can Provide Useful Context
Knowing that an unknown caller shares a WhatsApp group with you can be helpful.
It does not prove that the person is trustworthy, but it can explain why the person may be contacting you.
Conversely, discovering that an unfamiliar international number has no obvious connection to your account may encourage additional caution.
Context is not proof, but it can improve decision-making.
Security Features Must Remain Understandable
Another important challenge is user education.
A feature only helps when people understand what it means.
WhatsApp therefore faces a difficult balance: it needs to provide enough information to improve security without overwhelming users with technical terminology.
The best security controls often operate quietly in the background while giving users clear warnings when something deserves attention.
WhatsApp Is Building a Security Ecosystem
These announcements should not be viewed as isolated features.
Passkeys address authentication.
Stronger two-step verification adds another defensive layer.
Unknown-caller context addresses social engineering.
Together, they form a broader security ecosystem covering several stages of a potential attack.
The Most Important Change May Be Behavioral
Technology can block attacks, but behavior often determines whether an attack succeeds.
If a user sees an unfamiliar international number and decides not to answer, an attacker may lose their opportunity before the conversation even begins.
If another user refuses to share a verification code, the attacker may be stopped.
Security therefore works best when technology and user judgment reinforce one another.
Deep Analysis
The Authentication Battle Is Changing
The biggest story behind
Passkeys Represent the Direction of Travel
The industry is moving toward authentication that relies more heavily on cryptographic credentials stored and protected by trusted devices.
WhatsApp Has a Massive Security Responsibility
With hundreds of millions of daily interactions taking place on the platform, even relatively small improvements can affect an enormous number of people.
Account Recovery Is a Critical Moment
The moment someone attempts to recover an account is especially attractive to attackers because security systems often need to balance protection with accessibility.
Multiple Passkeys Improve Resilience
Having more than one passkey can reduce the risk of being locked out when users change devices or lose access to a particular device.
Stronger Passwords Close Another Gap
Expanding two-step verification beyond six numeric digits gives security-conscious users a significantly stronger credential option.
Complexity Still Requires Good Habits
A stronger password does not eliminate risk if the password is reused, predictable or shared with someone else.
Phishing Remains a Major Threat
Even the strongest platform authentication cannot completely eliminate attacks that manipulate people into voluntarily handing over access.
Caller Context Is a Defensive Signal
Information about unknown callers can give users additional evidence before they decide to engage.
Foreign Numbers Deserve Extra Attention
An unexpected international number is not automatically fraudulent, but it can be a useful warning signal when combined with other suspicious circumstances.
Shared Groups Add Social Context
Knowing that someone belongs to one of your groups can help explain why they might be contacting you.
Context Does Not Equal Trust
A scammer could potentially share a group with a target, so users should never treat shared membership as proof of legitimacy.
Scammers Exploit Urgency
Many fraud campaigns are successful because victims are pressured to act immediately.
Slowing the Victim Down Is Valuable
Even a few additional seconds of consideration can make it easier for someone to recognize suspicious behavior.
Messaging Apps Are Financial Targets
Criminals increasingly use messaging platforms to initiate payment scams, investment fraud and impersonation attacks.
Trust Is the Currency of WhatsApp
The
Compromised Accounts Become Launchpads
An attacker controlling one account can use its existing relationships to target additional victims.
Security Must Protect Relationships
The objective is not simply to protect a login. It is also to prevent compromised accounts from being weaponized against the victim’s contacts.
Passkeys Attack the Credential Problem
By reducing reliance on reusable secrets, passkeys address one of the fundamental weaknesses of traditional authentication.
Two-Step Verification Adds Defense in Depth
Security is stronger when attackers must overcome multiple independent barriers.
Android Gets an Early Advantage
The new unknown-caller context feature currently gives Android users a capability that iPhone WhatsApp users do not yet have.
Feature Parity Will Matter
WhatsApp will likely face pressure to bring equivalent security functionality to iOS.
Apple’s Approach Shows the Trend
Call Screening demonstrates that smartphone platforms are increasingly treating unknown communication as a security problem rather than merely a nuisance.
WhatsApp Has a Different Challenge
Unlike ordinary cellular calls, WhatsApp operates inside a social ecosystem involving accounts, groups, profiles and encrypted communications.
Privacy Must Remain Central
Security features should provide useful information without unnecessarily exposing sensitive information about users or their contacts.
Better Warnings Can Reduce Risk
Users do not always need technical explanations. Sometimes they simply need enough context to recognize that something unusual is happening.
Security UX Is Becoming Critical
The future of consumer cybersecurity will depend increasingly on how clearly platforms communicate risk to ordinary people.
Attackers Will Adapt
Every defensive improvement pushes criminals toward alternative techniques.
Social Engineering Will Remain Persistent
Even if passkeys become widespread, attackers will continue targeting human decision-making.
Recovery Systems Need Equal Protection
Strong login authentication can be undermined if account recovery is significantly weaker.
Users Should Enable Every Available Layer
The strongest protection comes from combining passkeys, two-step verification, device security and cautious behavior.
Unknown Calls Should Be Treated Carefully
Users should avoid sharing codes, passwords, financial information or sensitive personal details with unexpected callers.
WhatsApp Is Moving in the Right Direction
The combination of stronger authentication and better caller context represents a meaningful improvement in the platform’s defensive posture.
The Bigger Picture Is Passwordless Security
WhatsApp’s announcement reflects a broader industry transition toward authentication systems that are harder to phish and easier to use.
The Human Element Still Matters Most
No security technology can completely protect an account when a user is successfully manipulated into bypassing their own defenses.
The Next Battlefield Is Trust
As authentication becomes stronger, criminals will increasingly attempt to convince victims that malicious requests are legitimate.
Security Will Become More Invisible
The strongest consumer security features may eventually become largely automatic, detecting suspicious behavior without demanding constant attention from users.
WhatsApp Is Preparing for That Future
Today’s improvements suggest Meta is trying to make WhatsApp security more resistant to both technical attacks and human manipulation.
What Undercode Says:
A Significant Security Upgrade
WhatsApp’s latest security improvements are more important than they initially appear. The company is addressing authentication, account recovery and social engineering at the same time.
Passkeys Are the Strongest Part
The expansion of passkeys is arguably the most consequential announcement because it moves users away from authentication methods that are easier to phish.
Multiple Devices Change the Equation
Supporting more than one passkey makes the technology more practical for people who use multiple devices.
Stronger Two-Step Verification Matters
Allowing full alphanumeric passwords gives users a stronger alternative to the traditional six-digit PIN.
Security Cannot Depend on One Barrier
Attackers only need to find one weak point. Users therefore benefit from multiple independent layers of protection.
Unknown Calls Are an Underrated Risk
People often focus on malicious links and hacked passwords while overlooking the danger posed by convincing phone conversations.
Scammers Prefer Conversation
A live conversation can create emotional pressure much faster than a text message.
Context Can Break the Spell
Showing information before the user answers gives them a chance to recognize something unusual.
International Numbers Can Raise Questions
An unexpected foreign number should encourage caution, especially when the user has no reason to expect an international call.
Shared Groups Are Useful Clues
A shared group can provide context, although it should never be interpreted as proof that a caller is safe.
WhatsApp Needs More Anti-Fraud Controls
Account security is only one part of the larger fraud problem affecting messaging platforms.
Identity Verification Is Becoming More Important
As digital communication replaces traditional phone calls, people need better ways to determine who is actually contacting them.
Trust Is Easily Weaponized
Criminals understand that people are more likely to respond to messages from identities they recognize.
Compromised Accounts Create Chain Reactions
One successful takeover can generate multiple secondary scams.
Passkeys Can Interrupt the Chain
If an attacker cannot easily take over the original account, the downstream fraud campaign becomes much harder to launch.
User Education Remains Essential
Technology cannot replace basic security awareness.
Never Share Verification Codes
No legitimate support process should require users to casually hand over authentication codes to strangers.
Strong Passwords Still Matter
Users choosing the new two-step verification password option should use a unique credential rather than recycling an existing password.
Device Security Is Part of Account Security
A compromised or poorly protected device can undermine otherwise strong authentication.
Biometrics Add Convenience
Face and fingerprint authentication make strong security easier to use on supported devices.
Convenience Can Improve Adoption
When security is easier, more users are likely to enable it.
The Best Security Is Often Simple
Users should not have to understand cryptography to benefit from cryptographic authentication.
Meta Is Responding to a Real Threat
The increasing sophistication of online scams makes these improvements increasingly necessary.
Attackers Will Not Stop
Every new defense will encourage criminals to search for another route.
Social Engineering Will Grow
As technical barriers become stronger, manipulating users becomes comparatively more attractive to attackers.
Caller Warnings Could Become Standard
The idea of giving users contextual information before answering unknown calls could eventually become common across messaging platforms.
iOS and Android Competition Could Help
If WhatsApp expands these capabilities across both platforms, users could benefit from stronger and more consistent protection.
Security Features Must Avoid False Confidence
A warning system should help users make better decisions without implying that an unflagged call is automatically safe.
Privacy Must Remain Protected
Additional caller information should be carefully designed so security improvements do not create unnecessary privacy risks.
WhatsApp Is Moving Toward Layered Defense
Passkeys, two-step verification and caller context address different stages of an attack.
Layered Defense Is the Correct Strategy
No single security feature can stop every attack, but multiple protections can dramatically increase the effort required.
The Bigger Message Is Clear
Consumer messaging security is becoming increasingly sophisticated because criminals have made these platforms valuable targets.
WhatsApp Users Should Take Advantage
Users who have access to passkeys and stronger two-step verification should consider enabling them rather than waiting for an account takeover attempt.
Unknown Callers Deserve More Skepticism
If an unexpected caller creates urgency, asks for money or requests a verification code, the safest response is to stop and independently verify the request.
The Security Race Will Continue
WhatsApp’s announcement is another step in an ongoing battle between platforms trying to protect users and criminals looking for easier ways to exploit them.
Undercode’s Bottom Line
The most promising part of this update is not a single feature. It is the direction WhatsApp is taking: stronger authentication, more contextual warnings and fewer opportunities for attackers to exploit stolen credentials.
Verification Results
✅ WhatsApp has announced expanded passkey support, including the ability to use more than one passkey with the same account.
✅ WhatsApp has expanded two-step verification beyond a six-digit PIN to support stronger alphanumeric passwords with special characters.
✅ WhatsApp announced additional caller context for unknown contacts on Android, including information such as country and shared groups.
❌ The Android unknown-caller feature should not be interpreted as proof that an unknown caller is legitimate simply because contextual information is displayed.
Prediction
(+1) Passkeys Will Become the Default
Passkeys are likely to become increasingly common across major messaging platforms as companies attempt to reduce phishing and credential theft.
(+1) Account Takeovers Will Become Harder
As more users adopt passkeys and stronger two-step verification, criminals will face greater difficulty using stolen verification codes alone to seize accounts.
(+1) Caller Context Will Expand
WhatsApp is likely to continue developing contextual warnings and identity-related information for suspicious or unfamiliar communications.
(-1) Social Engineering Will Not Disappear
Criminals are likely to shift more attention toward convincing users to authorize actions themselves when technical account takeover becomes more difficult.
(+1) Security Will Become More Automatic
Future messaging platforms will likely rely increasingly on background detection, device-based authentication and contextual warnings that require less effort from users.
(-1) Attackers Will Search for Recovery Weaknesses
As authentication becomes stronger, account recovery and device-transfer processes could become increasingly attractive targets for criminals.
(+1) WhatsApp’s Security Model Will Become More Layered
The long-term direction points toward multiple overlapping defenses rather than relying on passwords, PINs or SMS verification alone.
▶️ Related Video (84% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: 9to5mac.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




