Executive brief
A vulnerability in WhatsApp's AI-powered Instagram Reel sharing feature could allow a sender to force a recipient's device to process media from an untrusted web link. This could be used to trigger specific apps or system functions on the victim's phone without their direct interaction. While this could lead to unauthorized data processing, there is no evidence that it has been used in active attacks.
Technical details
A vulnerability classified as Improper Verification of Source (CWE-940) exists in the handling of AI rich response messages for Instagram Reels. Due to incomplete validation of these messages, a remote attacker with basic user privileges can send a crafted message that forces the recipient's device to fetch and process media content from an arbitrary URL. This includes the ability to trigger OS-controlled custom URL scheme handlers, potentially leading to further exploitation of other installed applications or system services. The issue affects WhatsApp for iOS (v2.25.8.0 to v2.26.15.72) and WhatsApp for Android (v2.25.8.0 to v2.26.7.10).
Affected products
- Meta WhatsApp for iOS 2.25.8.0 to 2.26.15.72
- Meta WhatsApp for Android 2.25.8.0 to 2.26.7.10
Timeline
- 2026-05-01: disclosed
- 2026-05-01: advisory