Beautiful Virgin Islands

Monday, May 11, 2026

WhatsApp is fixing a bug in its desktop app that allowed access to files on your computer

WhatsApp is fixing a bug in its desktop app that allowed access to files on your computer

Last month, WhatsApp fixed a bug in its desktop app that allowed attackers to read files from your computer. A post published by security firm PerimeterX last night suggests the bug affected folks who used either WhatsApp’s Mac or Windows app paired with an iPhone.

The company’s security researcher, Gal Weizman, found vulnerabilities in WhatsApp’s Content Security Policy (CSP) that could be exploited to send manipulated messages and links using Cross-Site Scripting (XSS). He was able to take advantage of these flaws to send malicious code or read files from a computer’s local file system. That could’ve been quite harmful if someone stored sensitive documents on their machine.

The researcher was able to find and manipulate code from where messages are formed in the desktop app. He proceeded to forge a banner with a link preview to include a potentially malicious link.

Weizman suggested that WhatsApp shouldn’t use older version of Google’s chromium-browser platform to avoid such flaws. If you’re using WhatsApp on an iPhone and through its desktop app, you should update both, just to be safe.

You can read the technical details of how Weizman was able to bypass WhatsApp’s CSP here.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
The War Map: Professor Jiang’s Dark Theory of Iran, Trump, China, Russia, Israel, and the Coming Global Shock [Podcast]
The End of the Old Order [Podcast]
Labour Is No Longer a National Party [Podcast]
Lawyers vs Engineers: Why China Builds While America Litigates [Podcast]
The AI Gold Rush Is Coming for America’s Last Open Spaces [Podcast]
The Pentagon’s AI Squeeze: Eight Tech Giants Get In, Anthropic Gets Shut Out [Podcast]
AI Isn’t Stealing Your Job. It’s Dismantling It Piece by Piece.
Britain’s Democracy Is Now a Costume
Churchill’s Glass: The Drunk, the Doctor, and the Myth Britain Refuses to Sober Up From
The Met Gala Meets the Age of Billionaire Backlash
Russian Oligarch’s Superyacht Crosses Hormuz via Iran-Controlled Route
Gunfire Disrupts White House Correspondents’ Dinner as Trump Is Evacuated
A Leak, a King, and a Fracturing Alliance
Inside the Gates Foundation Turmoil: Layoffs, Scrutiny, and the Cost of Reputational Risk
UK Biobank Breach Exposes Health Data of 500,000, Listed for Sale on Chinese Platform
KPMG Cuts Around 10% of US Audit Partners After Failed Exit Push
French Police Probe Suspected Weather-Data Tampering After Unusual Polymarket Bets on Paris Temperatures
News Roundup
Microsoft lost 2.5 millions users (French government) to Linux
Privacy Problems in Microsoft Windows OS
News roundup
Péter András Magyar and the Strategic Reset of Hungary
Hungary After the Landslide — A Strategic Reset in Europe
Meghan Markle Plans Exclusive Women-Focused Retreat During Australia Visit
Starmer and Trump Hold Strategic Talks on Securing Strait of Hormuz Amid Rising Tensions
×