Source · Tier C · Blog / article

What we learned about TEE security from auditing WhatsApp's Private Inference

Trail of Bits. 2026. Trail of Bits blog.

Originalhttps://blog.trailofbits.com/2026/04/07/what-we-learned-about-tee-security-from-auditing-whatsapps-private-inference/
Accessed2026-09-25
NoteThe auditors' own summary of their pre-launch security review of WhatsApp Private Processing (AMD SEV-SNP with NVIDIA confidential GPUs); the post does not say who commissioned it. Reports 28 issues, eight of high severity, and describes environment variables and ACPI tables loaded outside the attestation measurement, patch levels trusted without checking AMD's certificates, and attestations with no freshness guarantee. Meta resolved 16 issues and partly addressed four before launch; the remaining eight are low or informational. States that the SEV-SNP threat model does not fully protect against advanced physical attacks, so Meta added controls on which CPUs are trusted (TOB-WAPI-10). The full report (https://github.com/trailofbits/publications/blob/master/reviews/2025-08-meta-whatsapp-privateprocessing-securityreview.pdf, dated August 2025) could not be read by the fetch tool on 2026-09-25; finding severities come from the library entry, S-3124.

Cited by

Search

Full search page