Skip to main content

WhatsApp fixed a spoofing flaw that could enable Remote Code Execution


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

April 8,  2025 By Pierluigi Paganini

 

WhatsApp addressed a flaw, tracked as CVE-2025-30401, that could allow attackers to trick users and enable remote code execution.

WhatsApp released a security update to address a vulnerability, tracked as CVE-2025-30401, that could let attackers trick users and enable remote code execution.

The spoofing flaw impacts WhatsApp for Windows before version 2.2450.6. An attacker could exploit the vulnerability by sending a file with a fake MIME type, tricking users into thinking it’s safe (e.g., an image), while it runs malicious code.

“A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension.” reads the advisory published by Meta. “A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp.”

 

>>Full Article<<

0 replies

Be the first to reply!

Reply