Meta is warning Windows users about a vulnerability in WhatsApp that could allow attackers to execute malicious code on their devices . Users are urged to update the messaging app to the latest version as soon as possible.

The vulnerability is tracked as CVE-2025-30401 and is a spoofing issue, which attackers can exploit by sending maliciously crafted files with modified file types to potential targets.
See also: Microsoft released Patch Tuesday April 2025
Meta says the vulnerability affected all WhatsApp versions and has been fixed in WhatsApp version 2.2450.6.
“A spoofing issue in WhatsApp for Windows displayed attachments according to their MIME type, but chose the file open based on the attachment’s filename extension,” WhatsApp explained.
“A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code instead of viewing the attachment when manually opening the attachment in WhatsApp“.
Meta says an external researcher found and reported the vulnerability through the Meta Bug Bounty.
Last July, WhatsApp faced a slightly similar issue that allowed Python and PHP attachments to execute without warning when recipients opened them on Windows devices with Python installed.
See also: Vulnerability in Nissan Leaf allows full control of the car
The above vulnerability is quite serious, so proactive protection is key to avoiding problems. To avoid similar (and other) issues in the future, follow these tips:
1. WhatsApp Instant Update
Go to the Microsoft Store (or the official WhatsApp website) and make sure you're using the latest version. Older versions may contain known vulnerabilities that attackers can exploit.
2. Use of Anti-virus / Anti-malware Software
Use a reliable antivirus program and update it regularly. It helps detect and prevent malware that can run through WhatsApp.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
3. Avoid Files from Unknown Sources
Don't open suspicious files, links, or videos you receive on WhatsApp, especially from unknown contacts. These can be carriers of malicious code.

4. Maintaining an Updated Operating System
Regularly update Windows. Many vulnerabilities are fixed by Microsoft itself. Don't ignore update notifications.
See also: CISA added CrushFTP vulnerability to KEV Catalog
5. Download the Application Only from Official Sources
- Always from the official site or Microsoft Store.
- Never from third-party websites or “broken” versions.
6. Be careful with public Wi-Fi
Avoid using WhatsApp (especially for calls or sending files) over unsecured public Wi-Fi, unless you are using a VPN.
7. Using Two-Step Verification
Enable 2-factor verification on WhatsApp from Settings > Account. It's an extra layer of security if someone tries to break into your account.
Source: www.bleepingcomputer.com
