CVE-2019-18426
KEV PoC massCross-Site Scripting and Local File Read in WhatsApp Desktop
CISA: WhatsApp Cross-Site Scripting Vulnerability
CVE-2019-18426 is a cross-site scripting flaw (CWE-79) in WhatsApp Desktop versions prior to 0.3.9309 which, when the desktop client is paired with WhatsApp for iPhone versions prior to 2.20.10, also permits reading local files on the machine running the desktop app. It is triggered when the victim clicks a link preview generated from a specially crafted text message, requiring no privileges but user interaction (CVSS 3.1: 8.2, AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). Successful exploitation runs attacker-controlled content in the desktop app's context, breaking out of the chat boundary and giving the attacker access to files on the victim's computer. Users running WhatsApp Desktop paired with an iPhone are affected, and Meta (then Facebook) remediated the flaw in WhatsApp Desktop 0.3.9309 and WhatsApp for iPhone 2.20.10. The bug is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), has a public proof-of-concept, and carries an EPSS score of 67.9% probability of exploitation within 30 days (99th percentile), indicating significant exploitation risk.
What to do: Update WhatsApp Desktop to version 0.3.9309 or later and WhatsApp for iPhone to version 2.20.10 or later, per vendor instructions. Inventory endpoints running the WhatsApp Desktop client and verify the versions of both the desktop app and the paired iPhone app, since the CISA KEV listing confirms active exploitation. Until patched, avoid clicking link previews from untrusted senders in WhatsApp Desktop.
| Meta Platforms WhatsApp Desktop | prior to 0.3.9309 |
| Meta Platforms WhatsApp for iPhone | prior to 2.20.10 (when paired with vulnerable WhatsApp Desktop) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
- Affected
- Meta Platforms WhatsApp
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N