SB2026050620 - Attachment spoofing in WhatsApp for Windows Desktop
Published: May 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Attachment spoofing (CVE-ID: CVE-2026-23863)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of attachments with embedded NUL bytes in the filename. A remote attacker can force the application to show a file to be of one type but once clicked will run as an executable, leading to a potential system compromise.
Remediation
Install update from vendor's website.