logo

Update WhatsApp now: Two new flaws could expose you to malicious files

ID: bb0944ac-1e1c-56c1-92fe-c94e22939194

STIX ID: report--bb0944ac-1e1c-56c1-92fe-c94e22939194

Feed Name: Malwarebytes Blog

Threat Score
35/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

...
...

### Executive Summary Meta/WhatsApp published patches for two vulnerabilities: CVE‑2026‑23866, which can cause WhatsApp to load media from attacker-controlled URLs (potentially triggering OS URL handlers), and CVE‑2026‑23863, where embedded NUL bytes in filenames on Windows can make executables appear as benign files. Users are instructed to update WhatsApp on Android, iOS, and Windows; the advisory states there is no evidence these bugs have been exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.