First published: Tue Jan 21 2020(Updated: )
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
Credit: cve-assign@fb.com cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Whatsapp Whatsapp | <2.20.10 | |
Meta Platforms WhatsApp | <0.3.9309 | |
Meta Platforms WhatsApp | ||
All of | ||
Whatsapp Whatsapp | <2.20.10 | |
Whatsapp Whatsapp For Desktop | <0.3.9309 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18426 is a cross-site scripting vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10.
Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 are affected by this vulnerability.
The severity of CVE-2019-18426 is high with a CVSS score of 8.2.
To fix CVE-2019-18426, update WhatsApp Desktop to version 0.3.9309 and WhatsApp for iPhone to version 2.20.10 or later.