First published: Sat Apr 05 2025(Updated: )
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp. We have not seen evidence of exploitation in the wild.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
<2.2450.6 | ||
<2.2450.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-30401 is high due to the potential for executing arbitrary code through spoofed file attachments.
To fix CVE-2025-30401, update WhatsApp for Windows to version 2.2450.6 or later.
CVE-2025-30401 can lead to security risks where users might inadvertently execute malicious files.
WhatsApp for Windows versions prior to 2.2450.6 are affected by CVE-2025-30401.
Yes, CVE-2025-30401 can be exploited remotely by sending malicious file attachments to users.