Technology & Science

India Issues High-Severity ‘GhostPairing’ Warning on WhatsApp Device-Linking Hijack

On 19-21 Dec 2025, CERT-In and Hyderabad police publicly flagged a new “GhostPairing” exploit that lets attackers gain full control of WhatsApp accounts via the Linked-Devices feature—no OTP, SIM swap, or password required.

By Priya Castellano

Focusing Facts

  1. CERT-In’s 19 Dec 2025 bulletin rates GhostPairing “High” severity and cites abuse of the “link device via phone number” workflow to seize accounts.
  2. Hyderabad Police Commissioner V.C. Sajjanar posted an alert on X on 21 Dec 2025 warning users to ignore messages such as “Hey, I just found your photo” and to audit their Linked Devices list.
  3. The scam re-uses legitimate 8-digit pairing codes or live QR codes, so victims receive no new-login OTP and attackers remain undetected for days or weeks.

See how 3 sources reported this story.

Where they agree. Where they disagree. What they left out.

  • Full multi-perspective analysis on every story
  • Primary source links for every claim
  • Daily email briefing — no algorithm

Perspectives in this article

  • Mainstream national news outlets
  • Hyderabad-based local press and police advisories
  • Business and financial newspapers
Share

Related Stories