Skip to content
COOEY

EXPOSURES › CVE-2019-18426

CVE-2019-18426

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-18426 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

WhatsApp Desktop paired with iPhone allows cross-site scripting and local file reading via CVE-2019-18426.

This XSS and local file read flaw in WhatsApp Desktop paired with iPhone exposes user data and enables script injection, directly impacting DIB compliance by violating data protection and system integrity requirements. Organizations must ensure all communication tools are patched and monitored for KEV-listed vulnerabilities to prevent data exfiltration and unauthorized access.

Shame score — A known vulnerability in a widely used communication tool that allows script injection and file reading, indicating a failure to patch or secure a critical user-facing application.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.