CVE-2019-18426
Meta Platforms WhatsApp
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
- CVSS
- 8.2
- EPSS
- 67.9% 99.3% percentile
- CISA KEV
- Listed
- Published
- 2020.01.22