← All CVEs

CVE-2019-18426

high · 8.2Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-23Remediation due 2022-06-13

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

8.2
CVSS
67.9%
EPSS (exploit prob.)
99th
EPSS percentile
2020-01-21
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
whatsappwhatsapp< 0.3.9309
whatsappwhatsapp< 2.20.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-18426