CVE-2026-23866: Medium severity WhatsApp WhatsApp for iOS vulnerability
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23866?
CVE-2026-23866 is classified as a high severity vulnerability due to its potential to exploit users' devices through malicious media content.
How do I fix CVE-2026-23866?
To mitigate CVE-2026-23866, users should update WhatsApp for iOS to version 2.26.15.73 or later and WhatsApp for Android to version 2.26.7.11 or later.
What versions of WhatsApp are affected by CVE-2026-23866?
CVE-2026-23866 affects WhatsApp for iOS versions 2.25.8.0 to 2.26.15.72 and WhatsApp for Android versions 2.25.8.0 to 2.26.7.10.
What type of attack does CVE-2026-23866 enable?
CVE-2026-23866 enables an attack where an arbitrary URL can be processed for media content on another user’s device.
Are there any known exploits related to CVE-2026-23866?
Currently, there are no public exploits confirmed for CVE-2026-23866, but the vulnerability's nature poses significant risk.