September 3, 2026
Bypassing WhatsApp Web’s Single-Session Restriction Using an Internal Fallback Endpoint
Hello World! I am Coy Emerald

By Coy Emerald
5 min read
A Lagos-based Cybersecurity Researcher and Ethical Hacker
I woke up today, 03/09/2026, with the mood of sharing one of my recent discoveries on Meta products, i.e. WhatsApp
First, this may already be a public knowledge to some few people, but I still feel that someone out there may find this information useful
As you should be aware, the "writer" on the bio of all my social media profiles, including on my Facebook account with the profile link https://facebook.com/coyemerald1, is really not there as a joke 😂**#NotHoax**
As a writer (that i am), I write for free, for a fee, and even for fun. That's why, if you take a moment to review any of my public profiles, including my X account, with the profile link https://x.com/@coyemerald1 you will surely read something there that will make you to laugh bi ẹ̀ni to la Molly 😂
It's morning here in Africa, Nigeria, as of the time I'm writing this, so I say, Good morning to anyone reading this!
And a quick reminder, especially to any of my fellow youths, the fresh minds, who may also be reading this piece, please avoid drug abuse
Now, let me share my discovery…
If you try to open multiple WhatsApp Web sessions via https://web.whatsapp.com/ within the same browser profile, you may encounter a message indicating that WhatsApp is open in another window. Click "Use here" to use WhatsApp in this window., prompting you to click "Use here" to continue using WhatsApp in the current window (see the attached screenshot)
This prompt is designed to prevent multiple WhatsApp Web sessions from operating simultaneously within the same browser profile, so I thought
Anyway, using Incognito mode abi Guest mode, or a separate browser profile may also allow users to access different WhatsApp accounts on WhatsApp Web
But attempting to login to another whatsApp account through web.whatsapp.com within the same browser profile will often trigger the "Use here" prompt (the same prompt displayed in the picture attached above) And by clicking on the "Use here" option, the active session will be transferred to the new window or tab, while the previous and active session session will be terminated
You can ask anyone in my country, Nigeria, I'm a responsible hacker, mo kì í ṣe màdàrù 😂 But ní alẹ́ ọjọ́rú (wednesday), Òṣù Kẹ́tà, ọdún 2026 yìí
During an independent security research, I reported a misbehavior to the Meta Security Team regarding WhatsApp, a discovery I came across while testing the internal WhatsApp endpoint https://web-fallback.whatsapp.com
During my testing, I observed that this endpoint https://web-fallback.whatsapp.com/ appeared to behave differently from the normal https://web.whatsapp.com/ environment by showing a QR code instead of a prompt displaying "WhatsApp is open in another window. Click 'Use here' to use WhatsApp in this window"
In all honesty, none of my students at O-Range Cybersecurity Academy would be afraid of scanning (even a malicious) QR code😂
And just like I told the participants in yesterday's cybersecurity class at 23 Taiwo Akinsanya, Oshodi/Isolo, Lagos, Nigeria, the essence of learning cybersecurity is to eliminate unnecessary fear while using the internet
After all, life itself is already full of fear; so using the internet should be something we should actually enjoy!
Anyway, for those interested in learning directly from me or becoming students of our Cybersecurity/Ethical Hacking class, I can personally be contacted on WhatsApp at +2349034847995 or via email at security@coyemerald.com
So, seeing this QR code on https://web-fallback.whatsapp.com simply appeared to me as a sign that something would go wrong 😂 as there was no pop-up/prompt triggering the usual "Use here" session-transfer warning or invalidating the existing session, as it normally does on https://web.whatsapp.com within the same browser profile
I took my phone, opened my WhatsApp account registered with the phone number +2349034847995, went to the "Linked Devices" option, clicked on "Link a device," and then scanned the QR code displayed on https://web-fallback.whatsapp.com
To my surprise, I was able to log in successfully to the same WhatsApp account. I logged out and repeated the same process with my other WhatsApp account, registered with my other phone number, +2347067864301 And again, the login was successful
What caught my attention, however, was that the other browser tab within the same browser profile, which already had my WhatsApp account associated with +2349034847995 linked through https://web.whatsapp.com, remained active
And everything there continued working perfectly, without the existing session being logged out
In my view, this created an apparent inconsistency between the session behavior and restrictions implemented on the primary WhatsApp Web platform, https://web.whatsapp.com
So, I responsibly reported this finding to the Meta Security Team on March 18, 2026
And their team acknowledged my report and initially requested that I refrain from publicly disclosing the information while they reviewed and investigated the reported behavior
Following several exchanges over the course of several months, the Security Team contacted me on Thursday, July 30, 2026, and concluded that the reported behavior did not constitute a security vulnerability
I respect their decision and acknowledge that not every unexpected or inconsistent behavior necessarily represents a security vulnerability.
However, I maintain my position regarding this observation that the QR-code authentication process available through this fallback endpoint https://web-fallback.whatsapp.com indeed bypass the session restriction enforced on https://web.whatsapp.com
As it allowed two separate WhatsApp accounts to be authenticated and operated simultaneously within the same browser profile without triggering session invalidation or the usual "Use here" warning
So this behavior appears inconsistent with the restrictions and user experience implemented on the primary WhatsApp Web platform
Anyway, the Meta Security Team has reviewed the report and concluded that the behavior does not meet their criteria for a Bug Bounty Program and won't take down this subdomain
So this article is therefore intended to document one of my security research findings in 2026 as this also demonstrates how different endpoints may exhibit different session-management behavior in web application
Once again, Good morning!
And please, don't forget to reach out to me if you ever require the services of a Cybersecurity Specialist abi Ethical Hacker , whether it's for Vulnerability Assessment and Penetration Testing (VAPT) or other Cybersecurity/Ethical Hacking-related services
And I also offer practical, hands-on training in Cybersecurity and Ethical Hacking for anyone interested in building real-world skills in the field of Information Security
My contact information is:
WhatsApp: +2349034847995 Email: security@coyemerald.com
And for more information about me and what I do, you can also visit my website: iam.coyemerald.com
Thanks for Reading!
Coy Emerald