
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23866 is a medium-severity vulnerability involving incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS and Android. It affects WhatsApp for iOS versions v2.25.8.0 through v2.26.15.72 and WhatsApp for Android versions v2.25.8.0 through v2.26.7.10. The flaw could allow a low-privileged user to trigger processing of media content from an arbitrary URL on another user's device, including activating OS-controlled custom URL scheme handlers. It was published on May 1, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, WhatsApp Advisory).
The root cause is classified as CWE-940 (Improper Verification of Source of a Communication Channel), meaning WhatsApp failed to properly validate the origin of AI-generated rich response messages associated with Instagram Reels previews. An attacker with a low-privilege account could craft malicious AI rich response messages containing arbitrary URLs; when processed by a vulnerable WhatsApp client, these messages could cause the victim's device to fetch media content from attacker-controlled URLs or invoke OS-level custom URL scheme handlers without user interaction. The attack vector is network-based with low attack complexity and no user interaction required, making it straightforward to trigger remotely (GitHub Advisory, WhatsApp Advisory).
Successful exploitation could result in limited confidentiality impact — specifically, unauthorized processing of media content from attacker-controlled URLs on a victim's device and potential invocation of OS-controlled custom URL scheme handlers, which could trigger unintended application actions or information disclosure. Integrity and availability are not directly impacted per the CVSS assessment. The scope is unchanged, meaning the impact is confined to the vulnerable WhatsApp application context, though custom URL scheme abuse could potentially interact with other installed applications on the device (GitHub Advisory, SecurityWeek).
No public proof-of-concept exploit code is known to exist, and Meta has stated there is no evidence of exploitation in the wild. The EPSS score is approximately 0.011% (2nd percentile), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low privileges (a valid WhatsApp account) but no user interaction on the victim's side, which slightly elevates the practical risk (GitHub Advisory, WhatsApp Advisory).
Meta has released patched versions addressing this vulnerability: WhatsApp for iOS v2.26.15.73 or later, and WhatsApp for Android v2.26.7.11 or later. Users should update their WhatsApp application immediately via the App Store or Google Play Store. No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation (WhatsApp Advisory, GitHub Advisory).
Meta disclosed this vulnerability alongside a companion flaw (CVE-2026-23863) in its May 2026 security advisory, prompting broad media coverage. Security outlets including SecurityWeek, Malwarebytes, GBHackers, and CyberSecurityNews covered the disclosure, generally characterizing the flaws as medium-severity but urging users to update promptly. Forbes noted Meta's proactive disclosure of two WhatsApp vulnerabilities in a new security advisory (Forbes, SecurityWeek, Malwarebytes). Community discussion on Reddit and security-focused Mastodon instances reflected general awareness but low alarm given the medium severity and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."