Security researchers have identified two significant vulnerabilities in WhatsApp that users should address promptly. The first flaw involves how media files and attachments are managed, while the second impacts Windows users of the messaging app. Although these vulnerabilities do not automatically infect devices, they could make it easier for cybercriminals to conduct social engineering attacks or exploit other vulnerabilities.
Malwarebytes experts cautioned that a malicious message could deceive a device into opening content from an untrusted source. The vulnerabilities, known as CVE-2026-23866 and CVE-2026-23863, were uncovered through Meta’s Bug Bounty program.
Despite no reported exploitation of these flaws in real-world attacks, WhatsApp has released an update as a precaution. Users are strongly advised to review their settings and ensure their app is up to date to stay protected.
To update WhatsApp, Android users can access the Google Play Store, search for WhatsApp Messenger, and select “Update.” iPhone users should open the App Store, navigate to WhatsApp under their profile icon, and choose “Update.” Once updated, devices will be safeguarded against potential threats.
In related news, older Android devices may soon lose WhatsApp access as the platform plans to discontinue support for versions preceding Android 6 starting September 8, 2026. Affected users may receive a notification indicating that WhatsApp will cease functioning on their devices later in the year. However, the impact is expected to be minimal, considering that Android 6 was released in 2015 and is rarely found on modern smartphones.