The Claim: Unencrypted WhatsApp Databases on Apple Devices
Security researchers at Mysk recently alleged that WhatsApp stores chat databases in an unencrypted form within an app group container on macOS and iOS. According to their findings, files such as Axolotl.sqlite, ContactsV2.sqlite, and LocalKeyValue.sqlite were discovered in a shared WhatsApp container, potentially accessible to other apps from the same developer. This claim has ignited a debate about whether end-to-end encryption truly protects user data once it reaches an Apple device.
The core of the allegation is that while messages are encrypted in transit, the local storage of decrypted data could leave them vulnerable to unauthorized access. If accurate, this would mean that anyone with physical access to an unlocked device—or a forensic tool—could recover sensitive information. The finding has prompted privacy advocates to question the robustness of Apple's sandboxing and the overall security of messaging apps on its platforms.
WhatsApp's Defense: Secure Containers and Limited Access
WhatsApp has pushed back against the broader interpretation of the claim, with WABetaInfo labeling it "misleading." The outlet argues that while the database may not be encrypted on the device, it resides in a secure container that only WhatsApp can access under normal system permissions. Furthermore, WABetaInfo disputed the notion that other Meta apps like Facebook and Instagram can access the WhatsApp database, stating that the shared container is designed to facilitate data migration between WhatsApp and WhatsApp Business, not cross-app data sharing.
This defense hinges on the effectiveness of Apple's app sandboxing, which restricts apps from accessing each other's data without explicit permissions. If the sandbox is functioning correctly, the risk of exposure is significantly lower. However, experts note that the issue could still pose a threat if an attacker gains elevated access or exploits an operating system flaw. The recent discovery of CVE-2026-28910, a macOS Archive Utility vulnerability, serves as a reminder that even well-designed sandboxes can be bypassed.
The Role of End-to-End Encryption: Protection in Transit vs. At Rest
End-to-end encryption (E2EE) is often touted as the gold standard for secure messaging, ensuring that only the sender and recipient can read the content. WhatsApp employs the Signal protocol to achieve this, meaning that messages are encrypted from device to device and cannot be intercepted by WhatsApp or third parties during transmission. However, E2EE does not automatically extend to data at rest—once a message is decrypted on a device, it may be stored in a readable format, depending on the app's design.
This distinction is crucial: E2EE protects data in transit but leaves the responsibility of protecting local storage to the app and the operating system. In WhatsApp's case, the local database appears to be unencrypted, which means that if an attacker can bypass device locks or exploit a vulnerability, they could access chat history. This is not unique to WhatsApp; many messaging apps store decrypted data locally for performance and functionality reasons. Nonetheless, the claim raises important questions about whether Apple's security measures are sufficient to safeguard such data.
Apple's Sandboxing: A Double-Edged Sword?
Apple's sandboxing architecture is designed to isolate apps from each other, preventing unauthorized access to user data. Each app runs in its own container, and app group containers allow related apps from the same developer to share data. While this is convenient for features like data migration, it also introduces potential risks if the container is not properly secured. The researchers' allegation suggests that WhatsApp's app group container might be accessible to other apps, though this is disputed.
Apple has not publicly commented on the specific claim, but the company has consistently emphasized its commitment to user privacy. The effectiveness of sandboxing depends on strict enforcement and the absence of vulnerabilities. In practice, sandbox escapes do occur, as evidenced by CVE-2026-28910. Therefore, users and organizations should not rely solely on sandboxing for protection; instead, they should adopt a layered security approach that includes strong device passcodes, biometric locks, and timely software updates.
Implications for Users: Balancing Convenience and Privacy
For everyday users, the WhatsApp local storage claim serves as a reminder that no messaging app is perfectly secure. While the risk of a targeted attack may be low, the potential consequences of a data breach can be severe. Users concerned about privacy can take practical steps to mitigate risks. Enabling disappearing messages for sensitive conversations reduces the window of exposure. Turning off "Save to Camera Roll" prevents media from being duplicated in the photo library. Activating Face ID or Touch ID app locks adds an extra layer of protection against physical access.
Additionally, regularly clearing chat media through WhatsApp's storage management tools can minimize the amount of data stored locally. It's also wise to avoid third-party backup tools that decrypt data locally, as they may introduce additional vulnerabilities. By adopting these measures, users can enhance their privacy posture without sacrificing the convenience of using WhatsApp.
What This Means for Businesses and Regulated Industries
For organizations in regulated industries such as finance, healthcare, and government, the local storage claim underscores the importance of endpoint security and mobile device management (MDM). Businesses that allow WhatsApp on managed devices should enforce strict policies: require strong passcodes, mandate biometric locks, ensure devices run the latest iOS and macOS versions, and enable encrypted backups. Furthermore, companies should consider whether WhatsApp's reported local storage model aligns with their compliance requirements, especially if they handle sensitive data.
WhatsApp offers a local storage feature for its Business API that allows businesses to specify where message data is stored at rest, which can help with data residency requirements. However, this feature applies to the Business API, not the consumer app, and may not address all concerns. Organizations should conduct a thorough risk assessment and explore alternative messaging solutions that offer stronger local encryption if needed.
Expert Perspectives: Disputes and Unresolved Questions
The security community remains divided on the severity of the claim. Some experts emphasize that the finding is not a vulnerability per se, but rather a design choice that relies on Apple's protections. They argue that the sandbox is robust enough for most threat models. Others point out that unencrypted local storage is a potential weak link, especially if an attacker gains physical access or exploits an OS flaw. The dispute highlights the need for transparency from WhatsApp and Apple regarding their security practices.
Until more details emerge, the practical takeaway is clear: end-to-end encryption protects transmission, but it does not guarantee encrypted local storage. Users and businesses must take proactive steps to secure their devices and data. As messaging apps continue to evolve, the balance between convenience and privacy will remain a critical topic, and claims like this one will drive further scrutiny and innovation in mobile security.
