logo

A WhatsApp bug lets malicious media files spread through group chats

ID: fd5324db-fe2b-5b2a-8fa8-2d3a22d38c8c

STIX ID: report--fd5324db-fe2b-5b2a-8fa8-2d3a22d38c8c

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2026-01-27

Date Updated: 2026-04-28

...
...

### Executive summary Google Project Zero disclosed a zero-click WhatsApp for Android vulnerability that allows an attacker to add a target to a newly created group and have malicious media automatically downloaded and used as an attack vector; Meta applied a partial server-side change but a full fix is pending. The report warns this is likely to be used in targeted campaigns, and provides actionable mitigations for users (disable automatic downloads, restrict who can add you to groups, and enable two-step verification).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.