Vulnerability record · CVE-2019-18426 · published 21 January 2020
CVE-2019-18426: WhatsApp Desktop link preview XSS and local file read
Whatsapp · Whatsapp
WhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. A victim must click a link preview in a specially crafted text message, so the flaw is reachable through ordinary messaging but needs that interaction. It matters because it is listed in CISA KEV and has a high EPSS probability, indicating real-world exploitation interest.
Description
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Automated analysis
high priorityIt is in CISA KEV with a high EPSS score and a public exploit, but exploitation requires the victim to click a link preview, which limits mass exploitation.
What it is
WhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. A victim must click a link preview in a specially crafted text message, so the flaw is reachable through ordinary messaging but needs that interaction. It matters because it is listed in CISA KEV and has a high EPSS probability, indicating real-world exploitation interest.
Impact
An attacker can execute script in the context of the WhatsApp Desktop client and read local files on the victim's machine. The CVSS scope change and high confidentiality impact reflect that the compromise can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted text message whose link preview the victim clicks; no authentication is required, but user interaction is required per the CVSS vector and description. The pairing of WhatsApp Desktop with WhatsApp for iPhone is part of the affected configuration.
Exploitation
CISA added this to KEV on 2022-05-23 with a remediation due date of 2022-06-13, and EPSS shows a 30-day probability of about 0.679 (99.3rd percentile). A public exploit reference exists on Packet Storm, so exploitation is known and observed.
What to do
- Update WhatsApp Desktop to 0.3.9309 or later and WhatsApp for iPhone to 2.20.10 or later per vendor instructions.
- Apply the vendor advisory guidance from Facebook/Meta for CVE-2019-18426.
- Treat the KEV due date as a hard deadline and verify both the desktop and paired iPhone clients are updated.
- Restrict or monitor use of unmanaged WhatsApp Desktop clients on corporate endpoints until patched.
Detection
- Hunt for WhatsApp Desktop versions below 0.3.9309 and paired iPhone versions below 2.20.10 in asset inventories.
- Monitor endpoint logs for WhatsApp Desktop spawning unexpected processes or accessing local files after link preview interaction.
- Review network or proxy logs for link preview fetches to unusual or attacker-controlled domains from WhatsApp Desktop.
- Alert on KEV-listed CVE-2019-18426 presence in vulnerability scan results until remediated.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-18426 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "WhatsApp Cross-Site Scripting Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157097/WhatsApp-Desktop-0.3.9308-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.facebook.com/security/advisories/cve-2019-18426 | Vendor Advisory |
| http://packetstormsecurity.com/files/157097/WhatsApp-Desktop-0.3.9308-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.facebook.com/security/advisories/cve-2019-18426 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-18426 | US Government Resource |
Track CVE-2019-18426 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-18426), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.