CVE-2019-18426 is a critical cross-site scripting (XSS) and local file reading vulnerability affecting WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10. This high-severity vulnerability (CVSS 8.2) requires user interaction, specifically clicking a malicious link preview, but allows for significant impact including confidential data disclosure. It is actively exploited in the wild, with public exploit code available on ExploitDB, and has garnered considerable community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.9309CPE matchmatch criteria | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:desktop:*:*:* | ||
< 2.20.10CPE matchmatch criteria | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.