ZeroHour

CVE-2019-18426

KEV PoC mass

Cross-Site Scripting and Local File Read in WhatsApp Desktop

CISA: WhatsApp Cross-Site Scripting Vulnerability

CVSS 3.1
8.2 high
EPSS
68%p99
Published
()
KEV added
AI analysis

CVE-2019-18426 is a cross-site scripting flaw (CWE-79) in WhatsApp Desktop versions prior to 0.3.9309 which, when the desktop client is paired with WhatsApp for iPhone versions prior to 2.20.10, also permits reading local files on the machine running the desktop app. It is triggered when the victim clicks a link preview generated from a specially crafted text message, requiring no privileges but user interaction (CVSS 3.1: 8.2, AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). Successful exploitation runs attacker-controlled content in the desktop app's context, breaking out of the chat boundary and giving the attacker access to files on the victim's computer. Users running WhatsApp Desktop paired with an iPhone are affected, and Meta (then Facebook) remediated the flaw in WhatsApp Desktop 0.3.9309 and WhatsApp for iPhone 2.20.10. The bug is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), has a public proof-of-concept, and carries an EPSS score of 67.9% probability of exploitation within 30 days (99th percentile), indicating significant exploitation risk.

What to do: Update WhatsApp Desktop to version 0.3.9309 or later and WhatsApp for iPhone to version 2.20.10 or later, per vendor instructions. Inventory endpoints running the WhatsApp Desktop client and verify the versions of both the desktop app and the paired iPhone app, since the CISA KEV listing confirms active exploitation. Until patched, avoid clicking link previews from untrusted senders in WhatsApp Desktop.

Affected
Meta Platforms WhatsApp Desktopprior to 0.3.9309
Meta Platforms WhatsApp for iPhoneprior to 2.20.10 (when paired with vulnerable WhatsApp Desktop)
Estimated exposure
masstens of millions of desktop users (WhatsApp has a 2B+ user base; fully vulnerable pairings now rare due to auto-updates) — WhatsApp serves over 2 billion users and the standalone desktop client is broadly deployed, so even a small share of desktop adoption puts potentially affected installations in the tens of millions, though the fully vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

CISA Known Exploited Vulnerability
Affected
Meta Platforms WhatsApp
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
whatsapp
Products
whatsapp
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

In the news