For years, “end-to-end encryption” has been the shield WhatsApp holds up whenever questions about security arise. While that encryption is robust, it only protects the data in transit. It doesn’t stop a malicious file from exploiting a vulnerability in the app’s code once it lands on your device. This week, Meta finally acknowledged that reality with a significant update that fundamentally changes how the world’s most popular messaging app handles security.
The headline feature is something called “Strict Account Settings.” Think of this as WhatsApp’s version of Apple’s Lockdown Mode. It is a specialised, optional setting designed for users who face genuine digital threats—journalists, activists, and government officials—but it is available to anyone who wants to trade a bit of convenience for peace of mind.

Activating this mode, which is tucked away under the “Advanced” tab in the Privacy settings, flips a switch that hardens the app against common attack vectors. Once enabled, WhatsApp stops playing nice with strangers. Messages from unknown numbers—those not already in your contacts—are stripped of their ability to auto-download media. That seemingly harmless video file from a random number is often the Trojan horse for spyware like Pegasus, and this setting effectively barricades that entry point.
The clampdown extends to link previews as well. In this mode, sending or receiving a URL won’t generate that helpful little thumbnail card. Generating those previews requires the app to fetch data from a website, which can leak your IP address or expose the app to malicious code hosted on that site. By killing the preview, WhatsApp eliminates the handshake that attackers often exploit. It also automatically silences calls from unknown numbers, further reducing the surface area for harassment or surveillance.
But the more interesting story is happening under the hood, where engineers are rewriting the DNA of the app itself. Meta revealed that it has migrated its media-sharing library, known internally as “wamedia,” from C++ to Rust. For the uninitiated, C++ is powerful but notorious for “memory safety” bugs—accidental errors in code that hackers can manipulate to crash an app or hijack a device. Rust is designed to be immune to these specific types of flaws by default.
This isn’t a small experiment. Meta claims this is the largest global rollout of a Rust-based library to date, replacing 160,000 lines of older code with a tighter, more secure 90,000-line Rust implementation. This runs across Android, iOS, and even the web version. It means that even if you don’t turn on the “Strict” settings, the core engine handling your photos and videos is mathematically less likely to have the kind of holes that mercenary spyware companies love to sell.

For the average user, these changes might feel invisible or, in the case of Strict Account Settings, slightly annoying. You might miss those link previews or get frustrated that a new client’s photo didn’t download automatically. But for the digital security landscape, this is a massive shift. It moves the responsibility of safety from the user having to spot a phishing link to the platform architecture itself being resilient enough to withstand the click.
The new “Strict Account Settings” are rolling out globally over the coming weeks. While most of us probably don’t need to live in a digital bunker, having the option to pull up the drawbridge when things feel unsafe is a feature long overdue.
