News thumbnail
Technology / Thu, 30 Jul 2026 LinkedIn

WhatsApp Brings End-to-End Encrypted Voice and Video Calls To The Web

WhatsApp has expanded its browser-based service with support for end-to-end encrypted voice and video calling, allowing users to make and receive calls through WhatsApp Web without downloading the company’s Windows or macOS applications. The update closes one of the most significant feature gaps between WhatsApp Web and the platform’s mobile and desktop applications. Voice and video calls without installing an applicationWeb Calling allows users to place and receive one-to-one and group voice or video calls from WhatsApp Web. WhatsApp Web must receive permission to access the microphone and camera before it can place a voice or video call. A person might begin a call on a phone while travelling and transfer it to WhatsApp Web after reaching a desk.

WhatsApp has expanded its browser-based service with support for end-to-end encrypted voice and video calling, allowing users to make and receive calls through WhatsApp Web without downloading the company’s Windows or macOS applications.

The update closes one of the most significant feature gaps between WhatsApp Web and the platform’s mobile and desktop applications. It also gives WhatsApp a more direct presence in the browser-based communications market, where services such as Microsoft Teams, Google Meet and Zoom have long allowed people to join calls without installing dedicated software.

WhatsApp announced the feature on July 28 alongside several other calling improvements, including transfers between devices, waiting rooms for group calls, faster activation of high-definition video and configurable background-noise suppression.

The company said the features are being introduced gradually and will become available to all users, although it did not provide a precise date for completing the global rollout.

Voice and video calls without installing an application

Web Calling allows users to place and receive one-to-one and group voice or video calls from WhatsApp Web. Once the feature reaches an account, users should also gain access to screen sharing, reactions and a dedicated Calls tab containing their call history and favourite contacts.

The browser can therefore operate as a more complete WhatsApp client rather than functioning mainly as an interface for messages, files and voice notes.

The change is particularly relevant to people working on devices where they cannot install software. This may include students using university computers, contractors working in tightly controlled environments and employees whose corporate laptops are subject to application allow-listing policies.

It could also make WhatsApp more convenient for occasional users who do not want another background application running on their computers. A user can open WhatsApp Web, link the browser to an existing account and access calling capabilities from the same interface used for messaging.

“Whether you’re a college student on a shared computer, using a work laptop that doesn’t allow app downloads, or simply prefer your browser, you can jump on a call without leaving the browser you’re already on,” WhatsApp said in its official announcement.

The company said browser-based calls are free, have no time limit and receive the same end-to-end encryption protections used by WhatsApp on other supported devices.

End-to-end encryption extends to the browser

End-to-end encryption is central to WhatsApp’s positioning of the new feature. Under that security model, the cryptographic material needed to decrypt a conversation remains with the participants’ devices rather than being available to WhatsApp in readable form.

The protection means an intermediary carrying the traffic should not be able to listen to the content of a properly encrypted call. WhatsApp says this remains the case when calls are made through its web service.

The company’s multi-device architecture assigns a separate identity key to every linked device. When a voice or video call is placed, the initiating client generates Secure Real-time Transport Protocol, or SRTP, secrets for the recipient’s eligible devices. Those secrets are encrypted before being delivered to each device.

When the recipient answers on one device, an encrypted media session is established using the secret generated for that device. WhatsApp has said the secret exists in the client’s memory for the duration of the call and is not available to its servers.

The process becomes more complicated for group calls. According to Meta’s technical explanation of WhatsApp’s multi-device architecture, a participant device generates the group’s SRTP secret and distributes it to the other active devices using pairwise end-to-end encrypted connections. The key is reset as participants enter or leave the call.

This architecture enabled WhatsApp to move beyond its older model, in which a linked computer largely depended on a connected smartphone. Companion devices can now communicate with the service independently while retaining device-specific encryption keys.

That distinction matters for browser calling. WhatsApp is not simply relaying decrypted audio and video from the user’s telephone to a web page. The browser session acts as a linked endpoint in the encrypted communications system.

Encryption does not eliminate endpoint risk

Although end-to-end encryption protects the call while it travels between participants, it does not make every browser or computer safe.

The audio and video must still be decrypted at each endpoint so participants can hear and see one another. Malware, a malicious browser extension, a compromised operating system or someone with access to an unlocked computer could potentially capture content after it has been decrypted.

That risk is especially important because WhatsApp has presented shared computers as one of the situations in which Web Calling may be useful.

Users accessing WhatsApp on a public, university or shared workplace machine should ensure they log out when finished and remove the browser from the list of linked devices. Simply closing a tab may not terminate an authenticated WhatsApp Web session.

WhatsApp’s multi-device security design allows users to view linked companion devices, check when they were last active and remotely log them out. This provides an important recovery mechanism if a user forgets to close a session or later suspects that a computer is no longer trustworthy.

Browser permissions are another consideration. WhatsApp Web must receive permission to access the microphone and camera before it can place a voice or video call. Screen sharing introduces additional exposure because a user may inadvertently reveal notifications, passwords, confidential documents or information displayed in other windows.

Corporate security teams may therefore need to review whether existing browser and data-loss-prevention policies adequately govern WhatsApp Web. An organisation that blocks installation of the WhatsApp desktop application may not necessarily intend to permit the equivalent calling and screen-sharing functionality through an approved browser.

The update could consequently create a policy gap in some managed environments. Security controls based only on installed applications may not account for communications tools that increasingly deliver comparable functionality as web applications.

End-to-end encryption can also complicate corporate monitoring and information-governance requirements. It protects the confidentiality of a conversation, but it does not provide an employer with the recording, retention, discovery or administrative capabilities commonly associated with approved enterprise conferencing platforms.

Waiting rooms give hosts greater control

WhatsApp is also adding a Waiting Room feature for calls created through shareable links.

When the organiser enables “Require approval to join,” people following the link are placed in a waiting area rather than being admitted immediately. The host can then decide who should enter the call and when.

This brings WhatsApp closer to the meeting-control model used by conventional videoconferencing services. It could be particularly useful when a call link has been forwarded beyond its intended audience, published in a group containing many members or exposed through a compromised account.

Call links reduce the friction involved in organising group conversations, but their portability also creates risk. Anyone who obtains a valid link may attempt to join unless the service applies additional access controls. Requiring approval gives the organiser an opportunity to identify unexpected participants before they enter an active discussion.

Waiting rooms should not, however, be treated as proof of identity. A displayed account name or profile photograph can help a host make a decision, but organisers discussing sensitive information should separately verify unfamiliar participants where appropriate.

The new feature builds on WhatsApp’s previous investment in group calling. The company introduced call links in 2022 and later added tools for scheduling calls and receiving notifications when participants join through a shared link.

Calls can now move between devices

Call Transfer is designed to let a participant move an active group call between a phone, tablet, desktop application and browser without disconnecting and dialling back in.

A person might begin a call on a phone while travelling and transfer it to WhatsApp Web after reaching a desk. The reverse process could allow someone to leave a computer and continue the conversation on a mobile device.

Device switching has become increasingly important as communications platforms attempt to provide a continuous experience across phones, tablets and computers. WhatsApp’s implementation is supported by the multi-device architecture it began introducing in 2021, which allowed linked clients to operate more independently of the primary phone.

The company’s announcement specifically describes transfers involving active group calls. It does not state whether identical functionality will be immediately available for every type of one-to-one call, and availability may vary during the phased rollout.

For security-conscious users, transferring a call also changes the endpoint handling decrypted content. Moving from a personal phone to a browser on a managed or shared computer may introduce different risks, even though the media remains end-to-end encrypted in transit.

QuickHD targets delays at the start of video calls

WhatsApp has also introduced a feature called QuickHD, intended to bring video calls to high-definition quality within the first few seconds.

Real-time communications services commonly adjust video quality dynamically according to available bandwidth, packet loss, processing capacity and network conditions. A call may begin at reduced quality while the service estimates the stability and capacity of the connection.

WhatsApp says QuickHD shortens this initial adjustment period so users receive a high-definition picture sooner. The company has not published detailed technical information about the feature’s resolution, bitrate thresholds, supported browsers or behaviour on constrained networks.

The improvement does not mean every call will remain in high definition. Real-time video systems generally continue adapting to network conditions, and quality may be reduced if bandwidth deteriorates or a device cannot process the stream reliably.

The benefit may be most visible on stable broadband connections, where users previously experienced a short period of blurred or low-resolution video despite having adequate capacity.

Noise suppression aims to improve calls in busy environments

A new noise-suppression control is intended to reduce background sounds and make speech clearer during calls.

WhatsApp said the feature can filter noise around the speaker, including sounds generated in busy or loud environments. Users can manage it through their in-call settings rather than having the processing permanently enabled.

Noise suppression may be useful for people calling from shared offices, cafés, transport hubs or homes where environmental sounds would otherwise interfere with speech.

The decision to make the setting controllable is significant because aggressive audio processing can occasionally remove wanted sounds, distort music or reduce the natural character of a voice. Users calling from quiet rooms or sharing non-speech audio may prefer to disable the feature.

WhatsApp has not said whether suppression occurs entirely on the user’s device or whether part of the processing is performed elsewhere. Any implementation must nevertheless preserve the platform’s claim that call content remains end-to-end encrypted.

IP privacy remains separate from content encryption

End-to-end encryption prevents WhatsApp or an intermediary from listening to call content, but it does not automatically conceal all connection metadata from other participants.

In direct peer-to-peer calling systems, each participant may need the other party’s Internet Protocol address to deliver media packets. An IP address can reveal a user’s internet provider and approximate geographical region.

WhatsApp previously introduced an optional “Protect IP Address in Calls” setting that routes calls through company servers. This prevents the other participant from seeing the user’s IP address, although the additional relay can reduce call quality because the traffic no longer follows the most direct route.

Meta has said relayed calls remain end-to-end encrypted and that WhatsApp cannot listen to their contents. Its technical description of the protection explains that the relay changes how traffic is transported without giving the server access to the media-encryption keys.

Users should therefore distinguish between encryption and IP protection. One secures the content of the call; the other limits the network information potentially exposed to another participant.

WhatsApp has not detailed in its Web Calling announcement how the IP-protection setting will be presented in browser sessions or whether existing account preferences will be applied automatically across linked devices.

A significant expansion of WhatsApp Web

WhatsApp first introduced encrypted one-to-one calling through its desktop application in 2021. It subsequently expanded desktop group calling, improved device synchronisation and launched dedicated applications with richer calling interfaces.

Moving the capability into the browser substantially lowers the barrier to access. Users no longer need administrative privileges to install an application, and WhatsApp can deliver updates to the web client without relying on an operating system’s software-distribution process.

The development also reflects the broader transition of browsers into full application platforms. Modern browsers provide camera and microphone access, real-time communications interfaces, screen capture, hardware acceleration and notification systems that previously required native software.

For WhatsApp, which says it protects communications for more than three billion users, reaching the browser could increase the role of its calling service in informal workplace collaboration as well as personal communication.

That expansion is likely to attract scrutiny from employers whose users already rely on WhatsApp outside approved corporate channels. The combination of encrypted calling, file exchange, screen sharing and access from unmanaged browsers can make the service convenient, but it can also make business communications more difficult to govern.

Organisations should decide whether WhatsApp Web is acceptable for professional use rather than allowing the policy to be determined accidentally by browser availability. Where it is permitted, employees should receive clear guidance on shared computers, screen sharing, linked-device reviews, sensitive discussions and the difference between consumer encryption and enterprise compliance controls.

WhatsApp said Web Calling, Call Transfer, Waiting Room, QuickHD and noise suppression are rolling out progressively. As a result, some users may see individual features before others, and the experience may differ temporarily between accounts, browsers and regions.

Frontier AI models are now finding healthcare vulnerabilities before a CVE exists. The exploit window used to be weeks. Now it is hours. Most security programs wait for a CVE to trigger the patch cycle. Mythos and Frontier AI based exploits skip that step entirely.

In this webinar, you’ll learn:

✅ How to meet the HIPAA NPRM 15-day patch mandate without disrupting clinical workflows

✅ How to govern BYOD and shared devices

✅ How to extend endpoint protection to telehealth, RPM, and home-care workers

✅ How to detect and contain open-source supply-chain threats such as npm and PyPI credential attacks that target EHR integrations and telehealth portals

✅ A multi-layered exposure management approach to pre-CVE exploitations that leverage frontier AI models such as Mythos

✅ A custom CISO dashboard built for healthcare

© All Rights Reserved.