Skip to content
COOEY

FAIL › dossier

WhatsApp

PRODUCT

· dossier confidence 20%

WhatsApp, owned by Meta, provides encrypted messaging but has demonstrated a pattern of high-severity remote code execution and cross-site scripting vulnerabilities in its VOIP and desktop stacks. These failures highlight persistent gaps in input validation and patching cycles for its communication protocols.

PROFILE
CategorymessagingWhat they doWhatsApp is a secure messaging app developed by Meta that allows users to send text, voice, and video messages, make calls, and share media over the internet. Websitehttps://www.whatsapp.com ↗
SECURITY POSTURE

Despite end-to-end encryption, WhatsApp has a history of high-severity remote code execution and cross-site scripting vulnerabilities, particularly in its desktop and VOIP stacks, indicating gaps in patching and input validation.

Notable failures
  • CVE-2025-55177: Unauthorized URL triggering RCE
  • CVE-2019-18426: XSS and local file reading on Desktop
  • CVE-2019-3568: VOIP stack buffer overflow RCE
Patterns: repeated unpatched edge-device and VOIP stack RCEs; cross-site scripting in desktop clients
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-04-19 CVE-2019-3568 high A buffer overflow in WhatsApp's VOIP stack allowed remote code execution via crafted RTCP packets.
2025-09-02 CVE-2025-55177 high Meta WhatsApp allowed unauthorized triggering of URLs on users' devices.
2022-05-23 CVE-2019-18426 high WhatsApp Desktop paired with iPhone allows cross-site scripting and local file reading via CVE-2019-18426.
DOSSIER SOURCES
Open questions: What is the exact founding year of WhatsApp? · What is the precise headquarters location of WhatsApp? · What is the current employee size of WhatsApp? · What is the exact website URL for WhatsApp?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:54:26.266362+00:00