CVE-2019-18426

HIGH KEV RANSOMWARE

WhatsApp Desktop <0.3.9309 - XSS

Title source: llm

Description

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

Exploits (3)

exploitdb WORKING POC
by Gal Weizman · textwebappsmultiple
https://www.exploit-db.com/exploits/48295
nomisec WRITEUP 11 stars
by HumanSecurity · client-side
https://github.com/HumanSecurity/CVE-2019-18426
inthewild WRITEUP
poc
https://github.com/perimeterx/cve-2019-18426

Scores

CVSS v3 8.2
EPSS 0.5526
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Details

CISA KEV 2022-05-23
VulnCheck KEV 2022-04-12
InTheWild.io 2020-02-07
ENISA EUVD EUVD-2019-8195
Ransomware Use Confirmed
CWE
CWE-79
Status published
Products (2)
whatsapp/whatsapp < 0.3.9309
whatsapp/whatsapp < 2.20.10
Published Jan 21, 2020
KEV Added May 23, 2022
Tracked Since Feb 18, 2026