← Vulnerability feed

Vulnerability record · CVE-2019-18426 · published 21 January 2020

CVE-2019-18426: WhatsApp Desktop link preview XSS and local file read

Whatsapp · Whatsapp

WhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. A victim must click a link preview in a specially crafted text message, so the flaw is reachable through ordinary messaging but needs that interaction. It matters because it is listed in CISA KEV and has a high EPSS probability, indicating real-world exploitation interest.

8.2 CVSS 3.1 High CISA KEV since 23 May 2022 EPSS 68% · top 0.7% CWE-79 · Cross-site scripting
8.2CVSS 3.1 base score, v2 5.8
68%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a high EPSS score and a public exploit, but exploitation requires the victim to click a link preview, which limits mass exploitation.

What it is

WhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. A victim must click a link preview in a specially crafted text message, so the flaw is reachable through ordinary messaging but needs that interaction. It matters because it is listed in CISA KEV and has a high EPSS probability, indicating real-world exploitation interest.

Impact

An attacker can execute script in the context of the WhatsApp Desktop client and read local files on the victim's machine. The CVSS scope change and high confidentiality impact reflect that the compromise can extend beyond the vulnerable component.

Attack surface

Reached over the network via a crafted text message whose link preview the victim clicks; no authentication is required, but user interaction is required per the CVSS vector and description. The pairing of WhatsApp Desktop with WhatsApp for iPhone is part of the affected configuration.

Exploitation

CISA added this to KEV on 2022-05-23 with a remediation due date of 2022-06-13, and EPSS shows a 30-day probability of about 0.679 (99.3rd percentile). A public exploit reference exists on Packet Storm, so exploitation is known and observed.

What to do

  • Update WhatsApp Desktop to 0.3.9309 or later and WhatsApp for iPhone to 2.20.10 or later per vendor instructions.
  • Apply the vendor advisory guidance from Facebook/Meta for CVE-2019-18426.
  • Treat the KEV due date as a hard deadline and verify both the desktop and paired iPhone clients are updated.
  • Restrict or monitor use of unmanaged WhatsApp Desktop clients on corporate endpoints until patched.

Detection

  • Hunt for WhatsApp Desktop versions below 0.3.9309 and paired iPhone versions below 2.20.10 in asset inventories.
  • Monitor endpoint logs for WhatsApp Desktop spawning unexpected processes or accessing local files after link preview interaction.
  • Review network or proxy logs for link preview fetches to unusual or attacker-controlled domains from WhatsApp Desktop.
  • Alert on KEV-listed CVE-2019-18426 presence in vulnerability scan results until remediated.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-18426 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "WhatsApp Cross-Site Scripting Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-18426 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3568WhatsApp VOIP stack heap buffer overflow allows remote code executionA heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number,…KEVEPSS 30%analysed5.4CVE-2025-55177WhatsApp iOS and Mac linked-device sync authorization flawWhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated…KEVEPSS 4.3%analysed9.8CVE-2022-36934Whatsapp heap-based buffer overflow vulnerabilityAn integer overflow in WhatsApp could result in remote code execution in an established video call.EPSS 2.4%9.8CVE-2021-24042Whatsapp heap-based buffer overflow vulnerabilityThe calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, W…EPSS 1.2%9.8CVE-2021-24041Whatsapp heap-based buffer overflow vulnerabilityA missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowe…EPSS 1.4%9.8CVE-2021-24026Whatsapp out-of-bounds write vulnerabilityA missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android …EPSS 1.4%9.8CVE-2020-1909Whatsapp use after free vulnerabilityA use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in …EPSS 2.3%9.8CVE-2020-1907Whatsapp out-of-bounds write vulnerabilityA stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2019-18426), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.