- Group chats on major messaging services are end-to-end encrypted but vulnerable to content manipulation by malicious group members or compromised devices.
- Attackers can send messages with the same ID but different content to different recipients, breaking transcript consistency.
- Examples include fake meeting invitations, manipulated polls, and hidden malware links disguised as harmless content.
- Researchers identified vulnerabilities in Threema, WhatsApp, iMessage, and Signal using modified clients.
- Pairwise communication allows direct manipulation; server fan-out can be forced to fall back to pairwise via intentional decryption failures.
- Services have not announced immediate fixes despite critical use cases like war-related political decisions.