CVE-2026-23866
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23866?
CVE-2026-23866 is classified as a high severity vulnerability due to its potential to exploit users' devices through malicious media content.
How do I fix CVE-2026-23866?
To mitigate CVE-2026-23866, users should update WhatsApp for iOS to version 2.26.15.73 or later and WhatsApp for Android to version 2.26.7.11 or later.
What versions of WhatsApp are affected by CVE-2026-23866?
CVE-2026-23866 affects WhatsApp for iOS versions 2.25.8.0 to 2.26.15.72 and WhatsApp for Android versions 2.25.8.0 to 2.26.7.10.
What type of attack does CVE-2026-23866 enable?
CVE-2026-23866 enables an attack where an arbitrary URL can be processed for media content on another user’s device.
Are there any known exploits related to CVE-2026-23866?
Currently, there are no public exploits confirmed for CVE-2026-23866, but the vulnerability's nature poses significant risk.