🔐
Security 📅 2026-08-26 · 04:00 AM IST ⏱ 3 min read

WhatsApp Embraces Passkeys to Shield Users From Fake Login Pages

WhatsApp rolls out passkey authentication on iOS and Android to prevent phishing attacks through stronger security verification methods.

WhatsApp Takes Major Step to Stop Fake Login Tricks

The popular messaging app WhatsApp is rolling out a new security feature designed to make it nearly impossible for criminals to steal your account through fake websites. The company has introduced passkeys—a modern authentication method—across both iPhone and Android devices. This development marks an important shift in how the platform protects user accounts from increasingly sophisticated phishing attempts.

Passkeys work differently from traditional passwords. Instead of typing a code that someone could intercept or guess, your device uses a unique digital signature tied directly to your phone. It's similar to how your fingerprint is unique to you—no two are identical. When you try to log in, your device confirms your identity through this signature rather than requiring you to remember and enter a password.

What This Means

For WhatsApp users, this change addresses one of the oldest tricks in the cybercriminal playbook: fake login pages. Scammers have long created bogus websites that look almost identical to the real WhatsApp login screen. When unsuspecting users enter their credentials on these fake sites, attackers gain full access to their accounts.

Passkeys eliminate this vulnerability almost entirely. Even if you land on a convincing counterfeit page, the passkey system recognizes that it's not the legitimate WhatsApp service and refuses to authenticate. It's like having a bouncer at a nightclub who can verify that you're actually at the real venue, not a fake one down the street.

Meanwhile, security researchers at Oasis Security have uncovered a separate but equally serious concern. They discovered that NVIDIA's NemoClaw—a component used in artificial intelligence systems—contains a flaw that could allow attackers to take control of AI agents running locally on computers. An attacker could potentially inject hidden instructions into the AI model itself, corrupting how it operates without anyone noticing.

Why You Should Care

Your WhatsApp account contains your complete conversation history, photos, and connections to everyone in your contact list. Losing access to it is more than just an inconvenience—it can lead to identity theft, fraud, and compromised relationships with friends and family.

The passkey rollout shows that WhatsApp is taking these threats seriously. By adopting this technology, the platform is moving away from older, weaker security methods that depend on you remembering complex passwords.

The NVIDIA vulnerability also matters to everyday users, even if you don't think you're running AI systems. Many software applications quietly use AI models in the background for everything from email filtering to photo organization. A compromised AI model could behave unpredictably or maliciously.

What You Can Do

These security improvements represent meaningful progress, but they work best when users understand the risks and take advantage of the protections offered to them.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →