Executive brief
A cross-site scripting (XSS) and local file reading vulnerability exists in WhatsApp Desktop when paired with WhatsApp for iPhone. The flaw is triggered when a victim clicks a link preview from a specially crafted text message, potentially allowing an attacker to execute arbitrary code or access local files.
Affected products
- WhatsApp WhatsApp Desktop prior to 0.3.9309
- WhatsApp WhatsApp for iPhone prior to 2.20.10
Timeline
- 2020-01-21: disclosed: NVD Published Date
- 2022-05-23: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog