{"id":51485,"date":"2026-05-05T09:44:28","date_gmt":"2026-05-05T09:44:28","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=51485"},"modified":"2026-05-05T09:44:28","modified_gmt":"2026-05-05T09:44:28","slug":"update-whatsapp-now-two-new-flaws-could-expose-you-to-malicious-files","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=51485","title":{"rendered":"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-05T14:13:17&#8243;,&#8221;description&#8221;:&#8221;Meta has published a new security advisory for messaging app WhatsApp, announcing patches for two vulnerabilities.\\n\\nWhatsApp has fixed two security flaws that could be abused to interfere with how media and attachments are handled on your device. There is no evidence that either bug has been exploited in the wild. \\n\\nThese bugs don\u2019t automatically infect devices, but they lower the barrier for social engineering and could be chained with other vulnerabilities for more serious attacks.\\n\\n## Malicious messages\\n\\nThe first issue, tracked as CVE\u20112026\u201123866, affects how WhatsApp processes AI\u2011generated \u201crich response messages\u201d that embed Instagram Reels. On affected iOS and Android versions, incomplete validation means a specially crafted message could cause the app to load media from an attacker\u2011controlled URL. In some cases, this could trigger operating system\u2011level custom URL scheme handlers. \\n\\nIn other words: a booby\u2011trapped message could prompt your device to open content from an untrusted source.\\n\\n### How to update WhatsApp for Android\\n\\nYou can easily update WhatsApp from the **Google Play Store**.\\n\\n  1. Open the Google Play Store\\n  2. Search for**** WhatsApp Messenger\\n  3. Tap **Update**\\n\\n\\n\\n**Note** : Updates may not be available immediately in all regions.\\n\\n### How to update WhatsApp on iOS\\n\\nTo update WhatsApp on iOS:\\n\\n  * Open the App Store\\n  * Tap your profile icon\\n  * Scroll to find WhatsApp and tap **Update**\\n\\n\\n\\nIf it&#8217;s not listed, search for WhatsApp to check if an \\&#8221;Update\\&#8221; button is available.\\n\\n## Misleading filenames\\n\\nThe second bug, CVE\u20112026\u201123863, affects WhatsApp for Windows before version 2.3000.1032164386.258709. \\n\\nIn this case, WhatsApp did not correctly handle filenames containing embedded NUL bytes. This could allow a file to appear as a harmless type in the interface while actually being treated as an executable when opened. That&#8217;s a classic recipe for social engineering: \u201cclick the PDF,\u201d but get an `.exe` file.\\n\\n### How to update WhatsApp for Windows\\n\\nYou can find your WhatsApp for Windows version number by clicking on your profile picture and selecting **Help and feedback**.\\n\\n![Version 2.3000.1038705703.261501](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/05\/version_wfW.png)Version 2.3000.1038705703.261501\\n\\nIf your version number is earlier than 2.3000.1032164386.258709, update via the Microsoft Store:\\n\\n  1. Click the **Start** menu and search for **Microsoft Store** to open it\\n  2. Click **Library** located at the bottom-left corner\\n  3. Find **WhatsApp Desktop**\\n  4. Click **Get Updates** or **Update**\\n\\n\\n\\nOnce installed, restart the app to apply the changes.\\n\\n### Automatic updates on Windows\\n\\nMy WhatsApp was already up to date because I have automatic updates turned on. Here&#8217;s how to turn it on:\\n\\n  1. Click the **Start** menu and search for **Microsoft Store** to open it\\n  2. Select **Profile**(your account picture) \\u003e **Settings**\\n  3. Make sure **App updates** is toggled to **On**\\n\\n![Auto updates on Windows](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/Auto_updates.png?w=593)\\n\\n* * *\\n\\n**Scammers  don&#8217;t need to hack you. They just need you to click once.** \\n\\nMalwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.&#8221;,&#8221;published&#8221;:&#8221;2026-05-05T11:39:11&#8243;,&#8221;modified&#8221;:&#8221;2026-05-05T11:39:11&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Update WhatsApp now: Two new flaws could expose you to malicious files&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2026-23863&#8243;,&#8221;CVE-2026-23866&#8243;],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:6.5,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:H\/A:N&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2026\/05\/update-whatsapp-now-two-new-flaws-could-expose-you-to-malicious-files&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-05T14:13:17&#8243;,&#8221;description&#8221;:&#8221;Meta has published a new security advisory for messaging app WhatsApp, announcing patches for two vulnerabilities.\\n\\nWhatsApp has fixed two security flaws that could be abused&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,26,12,115,21,13,7,11,5],"class_list":["post-51485","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-cvss-65","tag-exploit","tag-malwarebytes","tag-medium","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=51485\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-05-05T14:13:17&#8243;,&#8221;description&#8221;:&#8221;Meta has published a new security advisory for messaging app WhatsApp, announcing patches for two vulnerabilities.nnWhatsApp has fixed two security flaws that could be abused...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=51485\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-05T09:44:28+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE\",\"datePublished\":\"2026-05-05T09:44:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485\"},\"wordCount\":684,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-6.5\",\"exploit\",\"malwarebytes\",\"MEDIUM\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=51485#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485\",\"name\":\"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-05-05T09:44:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=51485\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51485#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=51485","og_locale":"en_US","og_type":"article","og_title":"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-05-05T14:13:17&#8243;,&#8221;description&#8221;:&#8221;Meta has published a new security advisory for messaging app WhatsApp, announcing patches for two vulnerabilities.nnWhatsApp has fixed two security flaws that could be abused...","og_url":"https:\/\/zero.redgem.net\/?p=51485","og_site_name":"zero redgem","article_published_time":"2026-05-05T09:44:28+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=51485#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=51485"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE","datePublished":"2026-05-05T09:44:28+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=51485"},"wordCount":684,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-6.5","exploit","malwarebytes","MEDIUM","news","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=51485#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=51485","url":"https:\/\/zero.redgem.net\/?p=51485","name":"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-05-05T09:44:28+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=51485#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=51485"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=51485#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Update WhatsApp now: Two new flaws could expose you to malicious files_MALWAREBYTES:544DB1D8FAB8646C12DB39FBFE087BDE"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/51485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=51485"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/51485\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=51485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=51485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=51485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}