CVE-2026-23863Disclosure(whatsapp / whatsapp)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch whatsapp whatsapp systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-158

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • whatsapp

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 14 mentions across 9 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 5 mentions (2026-06-01); latest day: 1
  • 14 total mentions across 9 days

Affected systems

Vendors
Products
whatsapp

Deep dive

Activity timeline14 mentions / 9d
01345Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-05-04: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-06-01: 5Mentions · 2026-08-06: 1Mentions · 2026-08-07: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-06-01: 3Patch / Workaround · 2026-08-06: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-06-01: 5Technical Details · 2026-08-06: 105-0105-0205-0405-0505-0605-0706-0108-0608-07
Signal classification4 categories
Disclosure
750.0%
Patch
428.6%
General
214.3%
Active Exploitation
17.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-011
Disclosure1
2026-05-021
Disclosure1
2026-05-041
Patch1
2026-05-052
General1Patch1
2026-05-061
Patch1
2026-05-071
Active Exploitation1
2026-06-015
Disclosure4Patch1
2026-08-061
Disclosure1
2026-08-071
General1
Full discourse14 posts
  • Md. Najeeb Hussain@mnh_18
    Disclosure

    The second WhatsApp flaw is genuinely sneakier: CVE-2026-23863 affected WhatsApp for Windows, involving improper handling of filenames containing embedded NULL BYTES. In plain English: a file could appear as a harmless PDF in your chat, but actually run as a program the moment you opened it. Genuinely clever attack. Genuinely important patch. 💻 #WhatsApp #Meta #Windows #Security

    Post summary

    The text announces a new WhatsApp Windows vulnerability (CVE-2026-23863) that allows arbitrary program execution via filenames with NULL bytes, noting a patch exists but without detail.

    01041371
    857 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 ثغرة في واتساب تسمح بتزييف الملفات التنفيذية تم استغلال ثغرة في واتساب لنظام التشغيل ويندوز، تسمح بتزييف الملفات التنفيذية كملفات من نوع آخر. وقد قامت واتساب بتصحيح هذه الثغرة الأمنية. تؤثر هذه الثغرة على مستخدمي واتساب، وقد تم الإبلاغ عنها من خلال CVE-2026-23866 و CVE-2026-23863. 🔗 للمزيد: https://www.security.nl/posting/935290/WhatsApp+dicht+spoofinglek+dat+uitvoerbare+bestanden+kon+vermommen?channel=rss

    Post summary

    WhatsApp’s CVE‑2026‑23866/23863 flaw allowed forged executable files on Windows; the vulnerability was actively exploited and subsequently patched by WhatsApp.

    00030298
    267 followersView on X
  • Chevalyetek@chevalyetek
    Patch

    2 fay (CVE-2026-23863 & ..-23866) te jwenn atravè pwogram bug bounty Meta e yo deja korije yo. Youn te ka kache yon fichye malveyan sou Windows, lòt la te ka ekzekite kontni depi yon URL etranje sou iOS/Android. Okenn eksplwatasyon pa detekte. Update WhatsApp ou! #Chevalyetek https://t.co/rf69fkRMeL

    Post summary

    Meta’s bug‑bounty program uncovered two CVEs (CVE‑2026‑23863 & CVE‑2026‑23866) that have now been fixed; no active exploitation has been detected.

    01020139
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23863 An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in … https://www.cve.org/CVERecord?id=CVE-2026-23863

    Post summary

    The post announces CVE‑2026‑23863, detailing an attachment spoofing flaw in WhatsApp for Windows that could enable maliciously formatted documents containing embedded NUL bytes; it provides technical details but no PoC, exploit, or mitigation information.

    00021178
    57.7K followersView on X
  • dano@danojbt
    General

    CVE-2026-23863

    Post summary

    The text lists only the CVE identifier CVE-2026-23863 without any supporting details.

    0000142
    8.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-23863 — Filename Manipulation & File Type Spoofing The Windows vulnerability exploited WhatsApp's handling of hidden control characters in filenames. When displaying attachments, the app failed to properly sanitize or validate the true file extension when…

    Post summary

    WhatsApp on Windows is vulnerable to filename manipulation via hidden control characters, leading to file type spoofing, but no proof‑of‑concept, patch, or active exploitation information is provided.

    1000053
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Meta disclosed two WhatsApp vulnerabilities — attachment spoofing in Windows (CVE-2026-23863) and AI-rich response command injection in Android/iOS (CVE-2026-23866) — both patched without evidence of wild exploitation. The Windows flaw could masquerade dangerous…

    Post summary

    Meta disclosed two WhatsApp CVEs, noted their patch status, and provided basic vulnerability type details without mentioning exploitation or a proof of concept.

    1000060
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What this means for your agents and systems: TL;DR Meta disclosed two WhatsApp vulnerabilities — attachment spoofing in Windows (CVE-2026-23863) and AI-rich response command injection in Android/iOS (CVE-2026-23866) — both patched without evidence of wild exploitation. The…

    Post summary

    Meta disclosed two WhatsApp vulnerabilities, CVE-2026-23863 and CVE-2026-23866, patched immediately with no evidence of in‑the‑wild exploitation.

    1000064
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-23863 (Windows): An attachment spoofing vulnerability in WhatsApp for Windows (prior to v2.3000.1032164386.258709) allowed a maliciously formatted document to exploit hidden characters in filenames. An attacker could craft a file that appeared to be a benign…

    Post summary

    The text announces a new Windows CVE involving attachment spoofing through hidden filename characters, providing basic technical details without mentioning PoC, exploit tools, active attacks, patches, or misclassification.

    1000061
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-23863 · v2.3000.1032164386.258709 The Messenger Becomes the Weapon: Meta Patches Two WhatsApp Vulnerabilities — Attachment Spoofing + AI-Rich RCE

    Post summary

    The announcement highlights Meta’s recent patch for two WhatsApp vulnerabilities: one involving attachment spoofing and a more serious AI‑rich remote code execution.

    1000057
    239 followersView on X
  • riccardo@ricca9380
    Patch

    @WABetaInfo Fixing CVE-2026-23863? 😇

    Post summary

    The tweet signals that @WABetaInfo is working on a fix for CVE‑2026‑23863, with no technical or exploitation details provided.

    0001087
    101 followersView on X
  • NOCTIS@NoctisIntel
    Patch

    PATCH NOW: WhatsApp CVE-2026-23863 + CVE-2026-23866 Both enable malicious file delivery via message 2B+ users affected Update managed endpoints + MDM devices now Watch: unexpected child procs from whatsapp.exe #CVE #ThreatIntel #CVE202623863 #CVE202623866

    Post summary

    The tweet urges users to patch WhatsApp for CVE‑2026‑23863 and CVE‑2026‑23866, noting that both vulnerabilities enable malicious file delivery and are actively exploited against more than 2 billion users.

    00000129
    9 followersView on X
  • Hannah Genie@hm_tech_travel
    General

    @The_Cyber_News Reels hype distracts from the real threat. That Windows CVE-2026-23863 lets attackers spoof documents. I keep Meta apps isolated on work devices here in Dubai.

    Post summary

    The text references Windows CVE‑2026‑23863 as a document‑spoofing vulnerability, offers no exploit or patch details, but mentions a personal mitigation practice.

    00000254
    67 followersView on X
  • Arnaud Mercier - #Entrepreneur #Versailles@arnaudmercier
    Disclosure

    A new Meta security advisory has disclosed two WhatsApp vulnerabilities, CVE-2026-23863 and CVE-2026-23866. Here’s what you need to know. https://www.forbes.com/sites/daveywinder/2026/05/02/meta-discloses-2-whatsapp-vulnerabilities-in-new-security-advisory/

    Post summary

    Meta announced that two new WhatsApp vulnerabilities, CVE-2026-23863 and CVE-2026-23866, were identified in a recent security advisory.

    0000055
    37.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwhatsappwhatsapp-windows-

Explore more