Skip to content
Meta Addresses Two Medium Severity Vulnerabilities in WhatsApp

Meta Addresses Two Medium Severity Vulnerabilities in WhatsApp

First seen 3 May 2026, 08:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 4, 2026 at 08:02 UTC
  • Two medium severity vulnerabilities in WhatsApp have been disclosed and patched.
  • CVE-2026-23863 involves attachment spoofing on Windows, while CVE-2026-23866 affects mobile apps.
  • No evidence of exploitation has been found, and users are urged to update their apps.

Meta has disclosed two vulnerabilities in WhatsApp, CVE-2026-23863 and CVE-2026-23866, in a security advisory published on May 1, 2026. Both vulnerabilities were discovered through Meta's bug bounty program and are rated as medium severity. CVE-2026-23863 affects WhatsApp for Windows and involves an attachment spoofing issue that could allow malicious files to masquerade as safe documents. CVE-2026-23866 impacts WhatsApp for iOS and Android, allowing unauthorized processing of media content via AI-rich responses for Instagram Reels. Fortunately, there is no evidence that these vulnerabilities were exploited in the wild, and both have been patched. Users are advised to update their apps to ensure protection against these threats. Meta has emphasized the importance of the security research community in identifying these issues before they could be exploited. The vulnerabilities were fixed in April and earlier this year, respectively.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 132d ago How this analysis works

Timeline

2026-01-01
CVE-2026-23863 patched for Windows
2026-04-01
CVE-2026-23866 patched for mobile apps
2026-05-01
CVE-2026-23863 and CVE-2026-23866 published

More articles in this cluster (13)

Following this threat?

Track CVE-2026-23863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed