WhatsApp Rolls Out Stricter Account Settings to Enhance Protection for High-Risk Users
- Jan 27
- 2 min read
Key Findings
Meta announced new Strict Account Settings on WhatsApp to enhance the security of high-risk users from advanced, targeted cyber attacks.
Strict Account Settings is a lockdown-style security feature that applies the most restrictive privacy settings, limits how the app works, and blocks attachments or media from people not in your contacts.
Meta is adopting the Rust programming language in WhatsApp's media sharing features to better protect photos, videos, and messages from spyware, calling it the largest global rollout of a Rust-based library.
The company is following a three-part strategy to address memory safety: reducing attack surface by design, strengthening security for existing C and C++ code, and using memory-safe languages by default for new development.
Additional protections include control-flow integrity, hardened memory allocators, and safer buffer handling, reinforcing WhatsApp's defense-in-depth approach.
Background
Meta announced new Strict Account Settings on WhatsApp to enhance the security of high-risk users from advanced, targeted cyber attacks. The company is taking this step to better protect individuals, such as journalists or public-facing figures, from sophisticated spyware by trading some functionality for enhanced security.
Strict Account Settings
Strict Account Settings is a lockdown-style security feature that applies the most restrictive privacy settings, limits how the app works, and blocks attachments or media from people not in your contacts. The company announced that the feature will roll out gradually and can be enabled via Settings > Privacy > Advanced.
Rust Adoption
Meta is also adopting the Rust programming language in WhatsApp's media sharing features to better protect photos, videos, and messages from spyware, calling it the largest global rollout of a Rust-based library. Rust enabled the creation of a secure, high-performance, cross-platform media library called "wamedia" to ensure media shared on the platform is consistent and safe across devices.
Memory Safety Initiatives
The company is following a three-part strategy to address memory safety: reducing attack surface by design, strengthening security for existing C and C++ code, and using memory-safe languages by default for new development. Additional protections include control-flow integrity, hardened memory allocators, and safer buffer handling, reinforcing WhatsApp's defense-in-depth approach.
Sources
https://securityaffairs.com/187405/security/whatsapp-rolls-out-strict-account-settings-to-strengthen-protection-for-high-risk-users.html
https://thehackernews.com/2026/01/whatsapp-rolls-out-lockdown-style.html


Comments