PT-2020-6682 · Whatsapp · Whatsapp Desktop+1

Published

2020-01-21

·

Updated

2025-10-24

·

CVE-2019-18426

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions WhatsApp Desktop versions prior to 0.3.9309 WhatsApp for iPhone versions prior to 2.20.10
Description The issue is related to a lack of protection in the web page structure, allowing for cross-site scripting attacks. Exploiting this issue requires the victim to click a link preview from a specially crafted text message, potentially enabling remote attackers to read files from the victim's local file system. The vulnerability was found to be related to JavaScript handling.
Recommendations For WhatsApp Desktop versions prior to 0.3.9309, update to version 0.3.9309 or later to resolve the issue. For WhatsApp for iPhone versions prior to 2.20.10, update to version 2.20.10 or later to resolve the issue. As a temporary workaround, consider avoiding clicking on link previews from unknown or untrusted sources in WhatsApp messages until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-04151
CVE-2019-18426

Affected Products

Whatsapp Desktop
Whatsapp For Iphone