CVE-2019-18426

Facebook WhatsApp Desktop

Published 21 Jan 2020 · updated 17 Jun 2026 · Analyzed

8.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 23 May 2022, with a remediation deadline of 13 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

References