CVE-2019-18426: WhatsApp Cross-Site Scripting Vulnerability
High severity, CVSS 8.2. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 67.9% chance of exploitation in the next 30 days.
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
Affected products
- WhatsApp WhatsApp: before 0.3.9309 (fixed in 0.3.9309); before 2.20.10 (fixed in 2.20.10)
Published 2020-01-21. Last modified 2026-06-17.