
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23863 is an attachment spoofing vulnerability in WhatsApp for Windows that allows maliciously crafted files with embedded NUL bytes in their filenames to appear as benign document types (e.g., PDFs) while executing as malicious binaries when opened. It affects WhatsApp for Windows versions prior to v2.3000.1032164386.258709 and was disclosed on May 1, 2026, by Meta. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, WhatsApp Advisory).
The root cause is classified as CWE-158 (Improper Neutralization of Null Byte or NUL Character), where WhatsApp for Windows fails to properly sanitize NUL bytes embedded in attachment filenames. An attacker can craft a file with a name such as document.pdf\x00.exe, causing the application to display the filename as a PDF while the underlying operating system processes it as an executable. Exploitation requires the victim to open the received attachment, making user interaction a necessary precondition. The attack vector is network-based with low complexity and requires no privileges on the attacker's side (GitHub Advisory, WhatsApp Advisory).
Successful exploitation allows an attacker to trick a user into executing an arbitrary binary disguised as a trusted document type, resulting in high integrity impact on the affected system. The malicious executable runs with the victim's user privileges, potentially enabling malware installation, data theft, unauthorized system access, or use of the compromised host as a pivot point for lateral movement. Confidentiality and availability are not directly impacted by the spoofing mechanism itself, though secondary payloads could affect all three pillars (GitHub Advisory, Malwarebytes).
No public proof-of-concept exploit code has been identified, and Meta has stated there is no evidence of exploitation in the wild (GitHub Advisory). The EPSS score is approximately 0.009–0.012%, placing it in the 2nd percentile for near-term exploitation likelihood. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of disclosure (GitHub Advisory, WhatsApp Advisory).
invoice.pdf\x00.exe, so that WhatsApp displays only the portion before the NUL byte.%USERPROFILE%\Downloads or %APPDATA%\WhatsApp) with filenames containing NUL bytes or mismatched extensions (e.g., displayed as .pdf but actual extension is .exe).cmd.exe, powershell.exe, unknown binaries).Users should immediately update WhatsApp for Windows to version 2.3000.1032164386.258709 or later, which contains the fix for this vulnerability (WhatsApp Advisory, GitHub Advisory). No configuration-based workaround has been published by Meta. As a precautionary measure, users should avoid opening attachments from unknown or untrusted contacts and verify file types through external means before opening. Security teams should enforce mandatory WhatsApp updates across all organizational Windows deployments.
Meta disclosed this vulnerability alongside a second flaw (CVE-2026-23866) via its security advisory program, prompting coverage from multiple outlets. SecurityWeek reported on the dual disclosure, describing it as a "file spoofing" issue (SecurityWeek). Malwarebytes urged users to update immediately, noting the potential for malicious files to masquerade as trusted documents (Malwarebytes). Forbes and other mainstream tech outlets covered the advisory, amplifying the update recommendation to general audiences (Forbes). Community sentiment on Reddit and LinkedIn reflected moderate concern, with emphasis on the user-interaction requirement limiting immediate risk.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."