VYPR

WhatsApp Desktop

by Facebook

CVEs (9)

  • CVE-2019-18426KEVJan 21, 2020
    risk 0.20cvss epss 0.61

    A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted…

  • CVE-2025-55177KEVAug 29, 2025
    risk 0.12cvss epss 0.01

    Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a…

  • CVE-2025-55179Nov 18, 2025
    risk 0.00cvss epss 0.00

    Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We…

  • CVE-2025-30401Apr 5, 2025
    risk 0.00cvss epss 0.00

    A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to…

  • CVE-2023-38538Oct 4, 2023
    risk 0.00cvss epss 0.00

    A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.

  • CVE-2023-38537Oct 4, 2023
    risk 0.00cvss epss 0.00

    A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.

  • CVE-2021-24042Jan 4, 2022
    risk 0.00cvss epss 0.01

    The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have…

  • CVE-2020-1889Sep 3, 2020
    risk 0.00cvss epss 0.01

    A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a remote code execution vulnerability inside the sandboxed renderer process.

  • CVE-2019-11928Sep 3, 2020
    risk 0.00cvss epss 0.00

    An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.