CVE-2019-18426highunder attackCWE-79

CVE-2019-18426: high-severity vulnerability in Facebook WhatsApp Desktop

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.2epss 68%
from disclosure to weapon39 days
Published on NVDJan 21
1st PoC+39d
CISA KEV+853d
exploitation probability
68%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2022-06-13

Apply updates per vendor instructions.

In short

WhatsApp Desktop had a security flaw that could allow attackers to run malicious code or read files on your computer if you clicked on a specially crafted link preview in a message. This is dangerous because attackers could steal your information or take control of your system.

Technical detail

CWE-79 cross-site scripting vulnerability in WhatsApp Desktop <0.3.9309 paired with iPhone <2.20.10 allows arbitrary script execution and local file access via malicious link previews. Attack requires user interaction (clicking preview); impact includes code execution in desktop client context and unauthorized file read access.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.