惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
Vercel News
Vercel News
aimingoo的专栏
aimingoo的专栏
T
Tailwind CSS Blog
罗磊的独立博客
B
Blog
博客园_首页
A
About on SuperTechFans
有赞技术团队
有赞技术团队
V
V2EX
U
Unit 42
I
InfoQ
IT之家
IT之家
博客园 - 司徒正美
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Stack Overflow Blog
Stack Overflow Blog
The Cloudflare Blog
H
Help Net Security

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Meta Discloses 2 WhatsApp Vulnerabilities In New Security...
Davey Winder · 2026-05-02 · via Forbes - Innovation
WhatsApp logo appears on screen of a smartphone  on top of a laptop keyboard.

Meta confirms two WhatsApp vulnerabilities in new security advisory.

NurPhoto via Getty Images

A new WhatsApp security advisory, published May 1, has confirmed two vulnerabilities that were discovered after being reported through Meta’s bug bounty program for the popular encrypted messaging app. Neither is known to have been exploited in the wild, and both have now been fixed by WhatsApp. Here’s what you need to know about CVE-2026-23863 and CVE-2026-23866.

Forbes2.8 Billion Credentials Stolen As Password Attacks Surge

WhatsApp Security Advisory—CVE-2026-23863 And CVE-2026-23866 Explained

As text message users absorb news of an SMS pumping attack that can rack up your phone bill in a matter of minutes, there’s never been a better time to switch to secure messaging apps such as Signal or WhatsApp. While not without security scares of its own, such as the recently reported phishing campaigns employing the encrypted messenger as part of the exploit chain, and a spyware threat targeting iOS users, the truth is that Meta does an excellent job of keeping the app and its users safe and secure.

If proof were needed, then look no further than the May 1 WhatsApp security advisory that has confirmed two vulnerabilities, both rated medium severity by the Common Vulnerability Scoring System. “Both were promptly fixed, and we have not seen evidence of exploitation in the wild,” a WhatsApp spokesperson told me. Both CVE-2026-23863 And CVE-2026-23866 were reported through WhatsApp’s official bug bounty program, which has been in operation for 15 years. “We continuously invest in hardening our systems and are grateful for the security research community's help in keeping WhatsApp safe,” the spokesperson said.

CVE-2026-23863 was patched earlier this year, WhatsApp told me, and was an “attachment spoofing issue in WhatsApp for Windows (prior to v2.3000.1032164386.258709)” that could have “allowed a maliciously formatted document with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened.”

CVE-2026-23866 was patched in April, and the vulnerability was an “incomplete validation of AI-rich response messages for Instagram Reels in WhatsApp for iOS (v2.25.8.0 - v2.26.7.22) and WhatsApp for Android (v2.25.8.0 - v2.26.7.10)” that could have “allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers.”

The good news is not only that the vulnerabilities were found before they could be exploited, but they have both been patched. “As always, we encourage everyone to keep their apps and devices up to date,” the WhatsApp spokesperson said.

ForbesGoogle Chrome Update Alert For All Users—4 Critical VulnerabilitiesBy Davey Winder