CVE-2026-23866
Analyzed
Analyzed - Analysis Complete
Improper URL Handling in WhatsApp for iOS and Android
Publication date: 2026-05-01
Last updated on: 2026-05-11
Assigner: Facebook, Inc.
Description
Description
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another userβs device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| From 2.25.8.0 (inc) to 2.26.7.10 (inc) | ||
| From 2.25.8.0 (inc) to 2.26.15.72 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-940 | The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin. |