LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-18426: WhatsApp Cross-Site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
CVSS 8.2 · High⚠ Actively exploited (CISA KEV)
8.2
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-18426 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

CVE-2019-18426 is a cross-site scripting vulnerability in WhatsApp Desktop when that client is paired with WhatsApp for iPhone. It can allow an attacker to run script in the Desktop context and read local files. For IT and security teams this matters because Desktop clients often sit on endpoints that hold business data, credentials, or access to internal resources; successful abuse of this class of flaw can lead to data exposure or further compromise of the workstation.

Public detail is limited to the CISA summary and the CWE classification. Confirm exact affected builds, fixed versions, and any configuration prerequisites against the vendor advisory before acting.

How it works

The weakness is CWE-79 (Improper Neutralization of Input During Web Page Generation), commonly called cross-site scripting. In this case the vulnerability exists in WhatsApp Desktop when it is paired with WhatsApp for iPhone. An attacker who can supply crafted content that the Desktop client processes can cause script to execute in the application’s context. Because the same flaw also permits local file reading, the script may be able to access files on the host that the Desktop process can reach.

Exact exploit mechanics, message formats, or required user interaction are not provided in the available facts. Treat any untrusted content delivered through the paired WhatsApp channel as potentially hostile until the client is updated, and verify technical details only from the vendor advisory.

Am I affected? How to find it in your systems

WhatsApp Desktop is typically installed on Windows or macOS endpoints used by staff who also run WhatsApp on an iPhone and have linked the two. Inventory steps:

Log or telemetry signs of exploitation are not detailed in the public facts. In general for this class, look for unexpected process behavior from the WhatsApp Desktop binary, unusual file-read activity by that process, or anomalous network connections originating from it. Confirm any detection guidance with the vendor advisory and your own EDR baselines.

How to remediate

Patch first. Apply the updates issued by Meta for WhatsApp Desktop exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

For hardening against the broader XSS and local-file-read class: keep the Desktop client auto-update enabled where policy allows, restrict the WhatsApp Desktop process to the minimum necessary file-system permissions, and treat the application as untrusted input handling software in your endpoint hardening baselines. Confirm any additional vendor-recommended configuration changes in the advisory.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

These measures only lower risk; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches even when ransomware use is not documented for this CVE. If you suspect the flaw was abused, preserve endpoint forensic data, rotate any credentials that may have been accessible to the Desktop process, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMeta Platforms · WhatsApp
WeaknessCWE-79
CVSS base score8.2 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
PublishedJan 21, 2020
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities