• News/
  • https://www.theregister.com/2025/04/08/whatsapp_windows_bug/

Don't open that JPEG in WhatsApp for Windows. It might be an .EXE

The Register
·
Jessica Lyons
·
Published Apr 8, 2025
·
Updated

A bug in WhatsApp for Windows can be exploited to execute malicious code by anyone crafty enough to persuade a user to open a rigged attachment - and, to be fair, it doesn't take much craft to pull that off. The spoofing flaw, tracked as CVE-2025-30401, affects all versions of WhatsApp Desktop for Windows prior to 2.2450.6, and stems from a bug in how the app handles file attachments. Specifically, WhatsApp displays attachments based on their MIME type - the metadata meant to indicate what kind of file it is - but when a user opens the file, the app hands it off based on its filename extension instead. That means something disguised as a harmless image with the right MIME type but ending in .exe could be executed as a program - if the user clicks it. "A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp," WhatsApp's parent company Meta explained in its security advisory. While WhatsApp is always an attractive target for miscreants, this particular bug does require user interaction – the victim has to manually open the malicious attachment for the payload to run. But this wouldn't be too hard, as many users are apt to click on anything - and even a savvy netizen may be inclined to open an attachment sent from, say, someone they didn't know but who belonged to their neighborhood watch WhatsApp group. A program run in this way may run into other ...

Read full article

Affected Software

4 affected components
Meta WhatsApp Desktop for Windows=2.2450.5
Meta WhatsApp Desktop for Windows=2.2450.4
Meta WhatsApp Desktop for Windows
Meta WhatsApp Desktop
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main vulnerability discussed in the article?

The article discusses a spoofing flaw in WhatsApp for Windows that allows malicious code execution through rigged attachments.

2

What potential attack vector does this bug create?

The bug can be exploited by persuading users to open a malicious JPEG attachment that is actually an executable file.

3

What versions of WhatsApp for Windows are affected by the bug?

The affected versions include WhatsApp Desktop for Windows 2.2450.4 and 2.2450.5.

4

What are the potential consequences of exploiting this vulnerability?

If exploited, the vulnerability could lead to unauthorized code execution on users' systems, posing significant security risks.

5

Who is the vendor responsible for WhatsApp Desktop for Windows?

The vendor responsible for WhatsApp Desktop for Windows is Meta.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203