WhatsApp Web calling rolls out as Meta warns of linked-device scams
WhatsApp Web is gaining browser-based voice and video calls, while Meta is also warning users about criminals abusing device-linking codes and QR codes. A suspicious request to link your account deserves the same caution as an unexpected request for an OTP, PIN or banking approval.

WhatsApp has started rolling out voice and video calling directly through WhatsApp Web, allowing people to make calls from a browser without downloading the desktop application. Meta announced the browser calling feature on July 28, saying it supports one-to-one and group audio and video calls, as well as screen sharing, reactions and a dedicated Calls tab. Calls made through WhatsApp Web are end-to-end encrypted, while Meta says the new features are being introduced gradually and should become available to all users.
The expansion comes months after Meta introduced additional safeguards against scams involving WhatsApp device linking. In March, the company warned that criminals may try to persuade account holders to enter a device-linking code or scan a QR code under false pretences, which can connect the victim’s WhatsApp account to the criminal’s device. WhatsApp now displays an alert when its systems detect signs that a linking request could be suspicious, including information about where the request originated.
The warning is relevant as WhatsApp becomes available for more functions through a browser, since encryption protects the contents of a call but cannot prevent someone from disclosing confidential information or approving a fraudulent request. South African banking customers are already being warned about scams in which criminals impersonate trusted organisations and create urgency before requesting an OTP, PIN or password, transaction approval, money transfer, QR-code scan or app installation. Standard Bank advises customers not to disclose these credentials, approve transactions they did not initiate or transfer money on instructions received through a call, message or email.
The South African Banking Risk Information Centre has issued similar advice about impersonation scams involving banking officials. SABRIC advises consumers to end the interaction and contact the bank through its official number if someone claims to represent the institution, while warning that banks do not request PINs, OTPs or banking passwords. The organisation has also warned that criminals are employing voice cloning, fake applications and other AI-assisted methods to make fraudulent communication more convincing.
WhatsApp Web users should therefore treat unexpected device-linking requests separately from the calls the service now supports. A QR code or linking code should not be entered on the instruction of an unknown person, and a suspicious request claiming to come from a bank should be verified directly with the institution through an official contact channel. End-to-end encryption protects communication within WhatsApp, while account security still depends on recognising attempts to gain unauthorised entry or obtain confidential information.





