CVE-2025-30401
Description
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp. We have not seen evidence of exploitation in the wild.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A spoofing vulnerability in WhatsApp for Windows prior to 2.2450.6 allows arbitrary code execution by exploiting a mismatch between MIME type and file extension when opening attachments.
Vulnerability
A spoofing issue exists in WhatsApp for Windows prior to version 2.2450.6. When an attachment is received, WhatsApp displays it according to its MIME type, but when the user manually opens the attachment, the file opening handler is selected based on the attachment's filename extension. An attacker can craft an attachment where the MIME type suggests a benign file (e.g., image) but the extension is executable (e.g., .exe), leading to a mismatch. [1]
Exploitation
An attacker sends a maliciously crafted attachment to a WhatsApp for Windows user. The recipient sees the attachment displayed as a safe type (e.g., an image) based on MIME type. When the recipient manually opens the attachment (e.g., by clicking on it), the operating system uses the file extension to determine the handler, potentially executing arbitrary code. No user interaction beyond opening the attachment is required. No authentication or special network position is needed beyond being able to send a message to the victim. [1]
Impact
Successful exploitation could allow an attacker to execute arbitrary code on the victim's Windows system with the privileges of the WhatsApp user. This could lead to full compromise of the affected system, including data theft, malware installation, or further lateral movement. The vulnerability is a spoofing issue that bypasses the visual indication of file type. [1]
Mitigation
The vulnerability is fixed in WhatsApp for Windows version 2.2450.6. Users should update to this version or later. No workarounds are available. There is no evidence of exploitation in the wild as of the advisory date. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 0.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.facebook.com/security/advisories/cve-2025-30401mitrex_refsource_CONFIRM
- www.whatsapp.com/security/advisories/2025/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.