FAIL › dossier
· dossier confidence 20%
WhatsApp, owned by Meta, provides encrypted messaging but has demonstrated a pattern of high-severity remote code execution and cross-site scripting vulnerabilities in its VOIP and desktop stacks. These failures highlight persistent gaps in input validation and patching cycles for its communication protocols.
PROFILE
CategorymessagingWhat they doWhatsApp is a secure messaging app developed by Meta that allows users to send text, voice, and video messages, make calls, and share media over the internet.
Websitehttps://www.whatsapp.com ↗
SECURITY POSTURE
Despite end-to-end encryption, WhatsApp has a history of high-severity remote code execution and cross-site scripting vulnerabilities, particularly in its desktop and VOIP stacks, indicating gaps in patching and input validation.
Notable failures
- CVE-2025-55177: Unauthorized URL triggering RCE
- CVE-2019-18426: XSS and local file reading on Desktop
- CVE-2019-3568: VOIP stack buffer overflow RCE
Patterns: repeated unpatched edge-device and VOIP stack RCEs; cross-site scripting in desktop clients
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-19 | CVE-2019-3568 | high | A buffer overflow in WhatsApp's VOIP stack allowed remote code execution via crafted RTCP packets. |
| 2025-09-02 | CVE-2025-55177 | high | Meta WhatsApp allowed unauthorized triggering of URLs on users' devices. |
| 2022-05-23 | CVE-2019-18426 | high | WhatsApp Desktop paired with iPhone allows cross-site scripting and local file reading via CVE-2019-18426. |
DOSSIER SOURCES
- Jan Koum - Forbes · www.forbes.com
- Brian Acton - Forbes · www.forbes.com
Open questions: What is the exact founding year of WhatsApp? · What is the precise headquarters location of WhatsApp? · What is the current employee size of WhatsApp? · What is the exact website URL for WhatsApp?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:54:26.266362+00:00