CVE-2019-18426
WhatsApp Cross-Site Scripting Vulnerability
- Published
- Jan 21, 2020
- Updated
- Oct 21, 2025
- Assigning CNA
- Evidence observed
- Apr 6, 2020
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NHigh · next 30 days
- Percentile
- 99.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.
Sources
3- CVE-2019-18426Research
CVE-2019-18426 disclosure repository detailing Open Redirect, CSP Bypass, Persistent XSS, and FS read permissions in WhatsApp, with technical articles and demo videos.
Proof-of-concept exploit and technical analysis for CVE-2019-18426, covering open redirect, CSP bypass, persistent XSS, and file system read in WhatsApp with potential for RCE.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.