Whatsapp

    Dashboard / Vendors

    Products: 7
    Vulnerabilities: 46
    Known Exploited: 0
    16
    Critical Level Threats
    13
    High Level Threats
    16
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-23866

    Unvalidated Media URL Processing Via WhatsApp AI Rich Response Messages

    Last Modified: May 11, 2026
    Published: May 01, 2026

    CVE-2026-23863

    WhatsApp Windows Filename Spoofing Leading to Potential Execution of Malicious Payload

    Last Modified: May 11, 2026
    Published: May 01, 2026

    CVE-2025-55179

    Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.

    Last Modified: Nov 25, 2025
    Published: Nov 18, 2025

    CVE-2025-55177

    Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

    Last Modified: Feb 26, 2026
    Published: Aug 29, 2025

    CVE-2025-30401

    A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp. We have not seen evidence of exploitation in the wild.

    Last Modified: Apr 09, 2025
    Published: Apr 05, 2025
    Items Per Page