CVE-2026-23866Disclosure(whatsapp / whatsapp)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch whatsapp whatsapp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-940

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • whatsapp

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-05-06); latest day: 1
  • 13 total mentions across 8 days

Affected systems

Vendors
Products
whatsapp

Deep dive

Activity timeline13 mentions / 8d
01223Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 3Mentions · 2026-05-07: 1Mentions · 2026-06-01: 3Mentions · 2026-08-25: 1Mentions · 2026-10-05: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-06-01: 2Patch / Workaround · 2026-08-25: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 1Technical Details · 2026-06-01: 3Technical Details · 2026-08-25: 105-0105-0205-0505-0605-0706-0108-2510-05
Signal classification3 categories
Disclosure
650.0%
Patch
433.3%
General
216.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-011
Disclosure1
2026-05-021
Disclosure1
2026-05-052
General1Patch1
2026-05-063
Disclosure1General1Patch1
2026-05-071
Patch1
2026-06-013
Disclosure2Patch1
2026-08-251
Disclosure1
Full discourse13 posts
  • Numb3rs@numbrs

    I've never worked on WhatsApp before, so I thought it'd be interesting to poke it with a stick! I wrote an article about my attempt to uncover WhatsApp's CVE-2026-23866: https://numb3rs.re/posts/cve-2026-23866-finding-a-whatsapp-nday/ This is my first article on mobile VR, let me know what you think!

    452222821517.9K
    383 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-23866 3 - CVE-2026-29014 4 - CVE-2026-23918 5 - CVE-2026-41940 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists the top five trending CVEs without providing any additional context, such as exploits, patches, or technical details.

    00032247
    1.7K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة في واتساب تسمح بتزييف الملفات التنفيذية تم استغلال ثغرة في واتساب لنظام التشغيل ويندوز، تسمح بتزييف الملفات التنفيذية كملفات من نوع آخر. وقد قامت واتساب بتصحيح هذه الثغرة الأمنية. تؤثر هذه الثغرة على مستخدمي واتساب، وقد تم الإبلاغ عنها من خلال CVE-2026-23866 و CVE-2026-23863. 🔗 للمزيد: https://www.security.nl/posting/935290/WhatsApp+dicht+spoofinglek+dat+uitvoerbare+bestanden+kon+vermommen?channel=rss

    Post summary

    The post reports a WhatsApp Windows vulnerability that allowed executable files to be spoofed, which has since been patched by the company.

    00030298
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-23866 (Android/iOS): A command injection flaw in the mobile versions of WhatsApp (Android and iOS) was linked to how the app processes "AI-rich responses" for Instagram Reels metadata. A threat actor could craft a specially formatted message that would force a…

    Post summary

    WhatsApp iOS/Android contains a command injection flaw (CVE-2026‑23866) that could enable attackers to run arbitrary commands via crafted messages; no PoC, exploit, patch or active exploitation details are provided.

    1000080
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Meta disclosed two WhatsApp vulnerabilities — attachment spoofing in Windows (CVE-2026-23863) and AI-rich response command injection in Android/iOS (CVE-2026-23866) — both patched without evidence of wild exploitation. The Windows flaw could masquerade dangerous…

    Post summary

    Meta disclosed two WhatsApp vulnerabilities (CVE‑2026‑23863 and CVE‑2026‑23866); both were patched, and no evidence of wild exploitation was reported.

    1000060
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    What this means for your agents and systems: TL;DR Meta disclosed two WhatsApp vulnerabilities — attachment spoofing in Windows (CVE-2026-23863) and AI-rich response command injection in Android/iOS (CVE-2026-23866) — both patched without evidence of wild exploitation. The…

    Post summary

    Meta disclosed two WhatsApp vulnerabilities that were promptly patched, with no indication of active exploitation.

    1000064
    239 followersView on X
  • Sam Stepanyan@securestep9
    General

    #WhatsApp Vulnerability CVE-2026-23866 Lets Attackers Leverage Instagram Reels to Execute Malicious URLs: 👇 https://cybersecuritynews.com/whatsapp-vulnerability-leverage-instagram-reels/

    Post summary

    The tweet references a new WhatsApp CVE (CVE-2026-23866) that allegedly allows attackers to exploit Instagram Reels for malicious URLs, but it provides no additional context, proof‑of‑concept, or evidence of active exploitation.

    00010291
    7.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23866 Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 c… https://www.cve.org/CVERecord?id=CVE-2026-23866

    Post summary

    The entry announces a new CVE for incomplete validation in WhatsApp’s AI response handling but contains no evidence of exploitation, PoC, patch, or debunking.

    00010141
    57.4K followersView on X
  • Md. Najeeb Hussain@mnh_18
    Disclosure

    Genuinely important technical detail on WhatsApp's patched Reels flaw (CVE-2026-23866): it stemmed from incomplete validation of AI-generated "rich response messages." AI-generated previews, genuinely becoming an attack surface. That's a brand new category of vulnerability that didn't exist three years ago. 🔐 #WhatsApp #Meta #CVE #AISecurity

    Post summary

    WhatsApp’s Reels flaw CVE‑2026‑23866 arises from incomplete validation of AI‑generated rich response messages, and the vulnerability has already been patched.

    00000111
    725 followersView on X
  • NOCTIS@NoctisIntel
    Patch

    PATCH NOW: WhatsApp CVE-2026-23863 + CVE-2026-23866 Both enable malicious file delivery via message 2B+ users affected Update managed endpoints + MDM devices now Watch: unexpected child procs from whatsapp.exe #CVE #ThreatIntel #CVE202623863 #CVE202623866

    Post summary

    The post announces that WhatsApp CVE-2026-23863 and CVE-2026-23866 allow malicious file delivery, urges immediate patching of managed endpoints and MDM devices, and notes potential suspicious child processes from whatsapp.exe.

    00000129
    9 followersView on X
  • get2cus@get2cus
    Disclosure

    @Malwarebytes The AI "feature-creep" on WhatsApp has opened a new attack vector. CVE-2026-23866 shows that embedding Instagram Reels via AI-generated messages can bypass URL validation, letting attackers trigger OS-level handlers without your consent. Complexity is the enemy of security

    Post summary

    The tweet reports a new WhatsApp vulnerability (CVE-2026-23866) that lets AI‑generated Instagram Reel messages bypass URL validation and trigger OS‑level handlers, but it does not provide a PoC, exploit code, or patch details.

    00000118
    49 followersView on X
  • Grok@grok
    Patch

    Yes, update WhatsApp now to the latest version. The patches for CVE-2026-23866 (and the Windows one) are client-side fixes in the app updates on the Play Store/App Store/Microsoft Store—not just server-side. No known exploits in the wild yet, but better safe. Check your app version and hit update.

    Post summary

    The post urges users to update WhatsApp to the latest app version, noting the client-side patch for CVE‑2026‑23866 and stating that no known exploits have been observed.

    00000114
    8.7M followersView on X
  • Arnaud Mercier - #Entrepreneur #Versailles@arnaudmercier
    Disclosure

    A new Meta security advisory has disclosed two WhatsApp vulnerabilities, CVE-2026-23863 and CVE-2026-23866. Here’s what you need to know. https://www.forbes.com/sites/daveywinder/2026/05/02/meta-discloses-2-whatsapp-vulnerabilities-in-new-security-advisory/

    Post summary

    The post announces that Meta has disclosed two WhatsApp CVEs (CVE-2026-23863 and CVE-2026-23866) but provides no technical specifics, PoC, exploit code, or patch information.

    0000055
    37.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appwhatsappwhatsapp-android-
Appwhatsappwhatsapp-iphone_os-

Explore more