FAIL › dossier
Meta Platforms
VENDOR· dossier confidence 50%
Meta Platforms is a major technology vendor whose WhatsApp ecosystem has suffered multiple high-severity remote code execution and cross-site scripting vulnerabilities, indicating a systemic weakness in its desktop and VOIP stack security.
PROFILE
CategoryTechnology / CommunicationsWhat they doMeta Platforms develops and operates social media and messaging platforms including WhatsApp, Facebook, and Instagram.
SECURITY POSTURE
Meta's security posture is compromised by a pattern of high-severity remote code execution (RCE) and cross-site scripting (XSS) vulnerabilities in its WhatsApp ecosystem, particularly affecting desktop clients and VOIP stacks.
Notable failures
- CVE-2025-55177: WhatsApp URL triggering RCE
- CVE-2019-18426: WhatsApp Desktop XSS & local file read
- CVE-2019-3568: WhatsApp VOIP stack RCE
Patterns: Repeated high-severity RCE in WhatsApp VOIP and desktop clients; Cross-site scripting and local file reading in WhatsApp Desktop
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-19 | CVE-2019-3568 | high | A buffer overflow in WhatsApp's VOIP stack allowed remote code execution via crafted RTCP packets. |
| 2025-09-02 | CVE-2025-55177 | high | Meta WhatsApp allowed unauthorized triggering of URLs on users' devices. |
| 2022-05-23 | CVE-2019-18426 | high | WhatsApp Desktop paired with iPhone allows cross-site scripting and local file reading via CVE-2019-18426. |
Open questions: Meta's current patching SLA for WhatsApp vulnerabilities · Whether Meta has implemented a bug bounty program for WhatsApp security
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:55:37.709587+00:00