Vulnerabilities

Critical WhatsApp bug lets hackers exploit file attachments on Windows

0

A critical security flaw has been discovered in WhatsApp Desktop for Windows, allowing attackers to execute malicious code through seemingly harmless file attachments. Tracked as CVE-2025-30401, this spoofing vulnerability affects all versions prior to 2.2450.6 and poses a serious risk to users who open attachments within the app.

The root of the issue lies in how WhatsApp processes file attachments. According to the official security advisory, the application displays attachments based on their MIME type but opens them based on the file extension. This inconsistency opened the door for threat actors to exploit the system.

For example, an attacker could send a file that appears to be an image (via its MIME type), but is actually an executable file (.exe) in disguise. If the user opens this file directly from WhatsApp, they could unknowingly launch malicious code.

As Facebook explained, “A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening it inside WhatsApp.”

This vulnerability is particularly dangerous because it plays on user trust. A recipient might see an image thumbnail or file icon and assume it’s safe—when in reality, it could trigger a hidden executable. The risk is even greater in group chats, where one malicious file could target multiple users at once.

Vulnerability Summary
Affected Versions : WhatsApp Desktop for Windows v0.0.0 to < v2.2450.6
Impact                    : Remote code execution via spoofed attachments
Exploit Method    : Malicious file with mismatched MIME type and extension
CVSS 3.1 Score      : High

All users of WhatsApp for Windows are strongly urged to update to version 2.2450.6 or later immediately. This update addresses the spoofing vulnerability and mitigates the risk of remote code execution through deceptive attachments.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

PoisonSeed exploits CRM tools to steal Cryptocurrency Wallets

Previous article

Hertz Data Breach: Driver’s Licenses and Financial Details at Risk

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *