Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Whatsapp whatsapp
|
|
| CPEs | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:* cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* |
|
| Vendors & Products |
Whatsapp whatsapp
|
Mon, 04 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Whatsapp
Whatsapp whatsapp For Android Whatsapp whatsapp For Ios |
|
| Vendors & Products |
Whatsapp
Whatsapp whatsapp For Android Whatsapp whatsapp For Ios |
Sat, 02 May 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unvalidated Media URL Processing Via WhatsApp AI Rich Response Messages |
Fri, 01 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-940 | |
| Metrics |
ssvc
|
Fri, 01 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 01 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild. | |
| References |
|
Status: PUBLISHED
Assigner: Meta
Published:
Updated: 2026-05-01T17:42:09.286Z
Reserved: 2026-01-16T19:49:26.309Z
Link: CVE-2026-23866
Updated: 2026-05-01T17:42:01.834Z
Status : Analyzed
Published: 2026-05-01T16:16:29.980
Modified: 2026-05-11T20:00:28.507
Link: CVE-2026-23866
No data.
OpenCVE Enrichment
Updated: 2026-05-04T16:07:30Z