CVE-2019-11928: WhatsApp Desktop

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.

Affected products

  • WhatsApp WhatsApp Desktop: before 0.3.4932 (fixed in 0.3.4932)

Published 2020-09-03. Last modified 2026-06-17.