Attachment spoofing in WhatsApp for Desktop (Windows) - CVE-2026-23863
Published: May 6, 2026
WhatsApp for Desktop (Windows)
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of attachments with embedded NUL bytes in the filename. A remote attacker can force the application to show a file to be of one type but once clicked will run as an executable, leading to a potential system compromise.