A critical security flaw has been discovered in WhatsApp Desktop for Windows, allowing attackers to execute malicious code through seemingly harmless file attachments. Tracked as CVE-2025-30401, this spoofing vulnerability affects all versions prior to 2.2450.6 and poses a serious risk to users who open attachments within the app.
The root of the issue lies in how WhatsApp processes file attachments. According to the official security advisory, the application displays attachments based on their MIME type but opens them based on the file extension. This inconsistency opened the door for threat actors to exploit the system.
For example, an attacker could send a file that appears to be an image (via its MIME type), but is actually an executable file (.exe) in disguise. If the user opens this file directly from WhatsApp, they could unknowingly launch malicious code.
As Facebook explained, “A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening it inside WhatsApp.”
This vulnerability is particularly dangerous because it plays on user trust. A recipient might see an image thumbnail or file icon and assume it’s safe—when in reality, it could trigger a hidden executable. The risk is even greater in group chats, where one malicious file could target multiple users at once.
All users of WhatsApp for Windows are strongly urged to update to version 2.2450.6 or later immediately. This update addresses the spoofing vulnerability and mitigates the risk of remote code execution through deceptive attachments.

















Comments