CVE-2019-18426
HIGH KEV RANSOMWAREWhatsApp Desktop <0.3.9309 - XSS
Title source: llmDescription
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
Exploits (3)
exploitdb
WORKING POC
by Gal Weizman · textwebappsmultiple
https://www.exploit-db.com/exploits/48295
nomisec
WRITEUP
11 stars
by HumanSecurity · client-side
https://github.com/HumanSecurity/CVE-2019-18426
References (3)
Scores
CVSS v3
8.2
EPSS
0.5526
EPSS Percentile
98.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Details
CISA KEV
2022-05-23
VulnCheck KEV
2022-04-12
InTheWild.io
2020-02-07
ENISA EUVD
EUVD-2019-8195
Ransomware Use
Confirmed
CWE
CWE-79
Status
published
Products (2)
whatsapp/whatsapp
< 0.3.9309
whatsapp/whatsapp
< 2.20.10
Published
Jan 21, 2020
KEV Added
May 23, 2022
Tracked Since
Feb 18, 2026