CVE-2025-30401
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than view the attachment when manually opening the attachment inside WhatsApp. We have not seen evidence of exploitation in the wild.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30401?
The severity of CVE-2025-30401 is high due to the potential for executing arbitrary code through spoofed file attachments.
How do I fix CVE-2025-30401?
To fix CVE-2025-30401, update WhatsApp for Windows to version 2.2450.6 or later.
What is the impact of CVE-2025-30401 on user security?
CVE-2025-30401 can lead to security risks where users might inadvertently execute malicious files.
Which versions of WhatsApp for Windows are affected by CVE-2025-30401?
WhatsApp for Windows versions prior to 2.2450.6 are affected by CVE-2025-30401.
Can CVE-2025-30401 be exploited remotely?
Yes, CVE-2025-30401 can be exploited remotely by sending malicious file attachments to users.