Skip to content
WhatsApp Addresses Instagram Reels URL Vulnerability, CVE-2026-23866

WhatsApp Addresses Instagram Reels URL Vulnerability, CVE-2026-23866

First seen 6 Oct 2026, 18:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 19:02 UTC
  • •CVE-2026-23866 allows URL redirection leading to IP address leakage.
  • •The vulnerability affects specific WhatsApp versions on iOS and Android.
  • •A researcher confirmed a one-click exploit but not the zero-click variant.

On October 6, 2026, Cyberkendra reported that WhatsApp patched CVE-2026-23866, a vulnerability allowing attackers to exploit Instagram Reels URLs to leak sensitive information like IP addresses and headers. The flaw, disclosed by Meta on May 1, 2026, affects WhatsApp versions 2.25.8.0 to 2.26.15.72 on iOS and 2.25.8.0 to 2.26.7.10 on Android. The vulnerability arises from incomplete validation of AI-rich response messages, which could let a crafted message redirect users to malicious URLs. A researcher, known as Numb3rs, confirmed a one-click attack vector but could not reproduce the more severe zero-click exploit. Meta has stated there is no evidence of exploitation in the wild. Users are advised to update to the latest WhatsApp versions to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-01
CVE-2026-23866 published
Meta disclosed the vulnerability affecting WhatsApp's handling of Instagram Reels, rating it medium severity with a CVSS score of 4.3.
Cyberkendra
2026-05-01
CVE-2026-23863 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
WhatsApp patches CVE-2026-23866
WhatsApp released updates to address the vulnerability affecting users on iOS and Android.
Cyberkendra

More articles in this cluster (2)

Following this threat?

Track Meta and CVE-2026-23863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which WhatsApp versions are affected?
Affected versions include WhatsApp for iOS from 2.25.8.0 to 2.26.15.72 and for Android from 2.25.8.0 to 2.26.7.10.
Is there evidence of exploitation?
Meta has stated there is no evidence of exploitation in the wild for this vulnerability.
What should users do?
Users should update to the latest version of WhatsApp to mitigate the risk associated with this vulnerability.