First published: Tue Jan 21 2020(Updated: )
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
Credit: cve-assign@fb.com cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
<2.20.10 | ||
<0.3.9309 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18426 is a cross-site scripting vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10.
Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 are affected by this vulnerability.
The severity of CVE-2019-18426 is high with a CVSS score of 8.2.
To fix CVE-2019-18426, update WhatsApp Desktop to version 0.3.9309 and WhatsApp for iPhone to version 2.20.10 or later.