Skip to content
COOEY

FAIL › dossier

Meta Platforms

VENDOR

· dossier confidence 50%

Meta Platforms is a major technology vendor whose WhatsApp ecosystem has suffered multiple high-severity remote code execution and cross-site scripting vulnerabilities, indicating a systemic weakness in its desktop and VOIP stack security.

PROFILE
CategoryTechnology / CommunicationsWhat they doMeta Platforms develops and operates social media and messaging platforms including WhatsApp, Facebook, and Instagram.
SECURITY POSTURE

Meta's security posture is compromised by a pattern of high-severity remote code execution (RCE) and cross-site scripting (XSS) vulnerabilities in its WhatsApp ecosystem, particularly affecting desktop clients and VOIP stacks.

Notable failures
  • CVE-2025-55177: WhatsApp URL triggering RCE
  • CVE-2019-18426: WhatsApp Desktop XSS & local file read
  • CVE-2019-3568: WhatsApp VOIP stack RCE
Patterns: Repeated high-severity RCE in WhatsApp VOIP and desktop clients; Cross-site scripting and local file reading in WhatsApp Desktop
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-04-19 CVE-2019-3568 high A buffer overflow in WhatsApp's VOIP stack allowed remote code execution via crafted RTCP packets.
2025-09-02 CVE-2025-55177 high Meta WhatsApp allowed unauthorized triggering of URLs on users' devices.
2022-05-23 CVE-2019-18426 high WhatsApp Desktop paired with iPhone allows cross-site scripting and local file reading via CVE-2019-18426.
Open questions: Meta's current patching SLA for WhatsApp vulnerabilities · Whether Meta has implemented a bug bounty program for WhatsApp security
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:55:37.709587+00:00