Comment by lxgr

5 hours ago

This is indeed a common vector of privacy leaks on either the recipient side (to the sender, in this case, if they operate the target of the link for which a preview is being rendered) or to the platform provider (if the preview is rendered server-side). But last time I checked, in WhatsApp, URL previews are rendered exclusively on the sender side and then sent as (E2E encrypted) media to the recipient.