Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Meta has disclosed and patched two medium severity security flaws in WhatsApp, affecting users on Windows, iPhone, and Android. The more critical vulnerability, CVE-2026-23863, allows malicious documents to appear harmless due to an attachment spoofing issue. This flaw affects WhatsApp for Windows v...
Meta has disclosed a medium-severity vulnerability in WhatsApp, tracked as CVE-2026-23866, which allows attackers to exploit the integration with Instagram Reels. This flaw enables remote threat actors to trigger arbitrary URL processing on victim devices without user consent by leveraging unvalidat...
Meta has disclosed two vulnerabilities in WhatsApp, CVE-2026-23863 and CVE-2026-23866, in a security advisory published on May 1, 2026. Both vulnerabilities were discovered through Meta's bug bounty program and are rated as medium severity. CVE-2026-23863 affects WhatsApp for Windows and involves an...