It suffices to send you an injected message.
See: https://invariantlabs.ai/blog/whatsapp-mcp-exploited#experim...