CVE-2019-18426: high-severity vulnerability in Facebook WhatsApp Desktop
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
WhatsApp Desktop had a security flaw that could allow attackers to run malicious code or read files on your computer if you clicked on a specially crafted link preview in a message. This is dangerous because attackers could steal your information or take control of your system.
CWE-79 cross-site scripting vulnerability in WhatsApp Desktop <0.3.9309 paired with iPhone <2.20.10 allows arbitrary script execution and local file access via malicious link previews. Attack requires user interaction (clicking preview); impact includes code execution in desktop client context and unauthorized file read access.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.