WhatsApp Flaw Lets Attackers Use Instagram Reels to Trigger Malicious URLs
ID: eaa747a7-1819-55be-b502-0549c3c1f575
STIX ID: report--eaa747a7-1819-55be-b502-0549c3c1f575
Feed Name: Cyber Press
WhatsApp disclosed two vulnerabilities: CVE-2026-23866 affects iOS and Android by allowing malicious Instagram Reels previews to fetch attacker-hosted media and trigger OS URL handlers (enabling phishing/tracking and potential follow-on attacks), and CVE-2026-23863 impacts WhatsApp for Windows by using NUL bytes in filenames to disguise executables as safe documents; both were fixed after bug-bounty reports and no active in-the-wild exploitation has been observed, so users should update and exercise caution with media and attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
