Junglewise Threat Intelligence

CVE-2019-18426: WhatsApp Cross-Site Scripting Vulnerability

CVE-2019-18426 · Severity: critical · CVSS 8.2 · Exploited in the wild · Published 2022-05-23

Technologies: Meta Platforms WhatsApp. Vendors: Meta Platforms.

Executive brief

A cross-site scripting (XSS) and local file reading vulnerability exists in WhatsApp Desktop when paired with WhatsApp for iPhone. The flaw is triggered when a victim clicks a link preview from a specially crafted text message, potentially allowing an attacker to execute arbitrary code or access local files.

Affected products

  • WhatsApp WhatsApp Desktop prior to 0.3.9309
  • WhatsApp WhatsApp for iPhone prior to 2.20.10

Timeline

  • 2020-01-21: disclosed: NVD Published Date
  • 2022-05-23: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog

Related threats