Meta has released two new security advisories for WhatsApp , revealing vulnerabilities that were quietly patched earlier this year. While the company says there is no evidence that the vulnerabilities were exploited in real-world attacks, their nature highlights the growing challenges facing messaging platforms in an environment where cybersecurity is under constant pressure.

The two vulnerabilities, affecting different versions of WhatsApp on Windows, iOS and Android, highlight issues related to both file management and the application's interaction with external content through artificial intelligence and redirection mechanisms.
The CVE-2026-23863 vulnerability and the risk of deceptive attachments
The first vulnerability, codenamed CVE-2026-23863, affected WhatsApp for Windows in versions prior to 2.3000.1032164386.258709 and was rated as moderate severity.
The issue was identified in the way the application handled filenames that contained embedded NUL characters. These characters, while invisible to the end user, could be used by an attacker to spoof a file's visible extension.
See also: WhatsApp is planning its own cloud backup system
In practice, a user could receive a file that appeared to be a harmless PDF document or image , when in fact it was an executable file . Upon opening it, malicious code could be activated , giving attackers access to the system or the ability to install malware.
This particular technique is not new in the field of cybersecurity, however, its appearance on such a widespread platform as WhatsApp highlights how easily even well-known methods can reappear through different technical paths.

The second vulnerability is related to AI responses and URL redirects
The second vulnerability, CVE-2026-23866, affected WhatsApp for iOS versions 2.25.8.0 to 2.26.15.72 and WhatsApp for Android versions 2.25.8.0 to 2.26.7.10.
According to Meta's technical description, the issue was related to incomplete validation of AI rich response messages related to Instagram Reels. This vulnerability could allow an attacker to trigger the processing of media content from arbitrary URLs on the victim's device.
Although Meta did not provide further details, security experts point out that such vulnerabilities can be used for complex redirection attacks.
Why custom URL schemes are considered a serious risk
The most concerning aspect of this vulnerability is the possibility of enabling custom URL schemes controlled by the operating system. This means that an attacker could theoretically cause other applications to launch on the user's device or redirect them to phishing pages that mimic trusted services.
See also: WhatsApp Plus: Meta tests subscription service
URL schemes such as facetime:, tel:, itms-apps: or deep links to third-party applications can be exploited for social engineering, deception, or even interaction with device functions that the user considers safe.
In a mobile device environment, where users often uncritically trust links opened through familiar applications, such gaps take on particular significance.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
WhatsApp: Artificial intelligence creates new attack surfaces
Meta's reference to "rich AI response messages" illuminates another dimension: the increasing integration of artificial intelligence mechanisms into everyday communication applications.
As platforms add capabilities to create, edit, and display intelligent content, new attack surfaces are created that did not exist in traditional messaging app architectures.
The interconnection between WhatsApp, Instagram and AI-based experiences can offer improved functionality to users, but it also increases the complexity of the code and, by extension, the chances of security vulnerabilities.

Responsible Disclosure via Meta Bug Bounty
Meta announced that both security vulnerabilities were discovered by anonymous researchers through the Meta Bug Bounty, reaffirming once again the importance of collaborating with the security research community.
See also: WhatsApp: Italian spyware company created fake iOS version
Vulnerability bounty programs have evolved into a critical tool for identifying vulnerabilities before they are exploited by malicious actors.
What users should do
While there is no evidence of active exploitation, the disclosure of these vulnerabilities is a clear reminder of the importance of regular updates.
Users are urged to always keep WhatsApp updated to the latest available version , avoid opening suspicious attachments and be particularly careful with links that activate external applications.
In an era where messaging apps are transforming into multifunctional digital hubs, security is no longer just a technical feature, but a fundamental prerequisite for trust.
