Skip to content

WhatsApp vulnerabilities

In our reporting, WhatsApp appears primarily in the context of user account compromise through fraud and cyber espionage. The main focus is on a new scam method abusing the 'Linked devices' feature to hijack accounts without stealing passwords, alongside targeted cyber espionage campaigns by suspected Russian threat clusters leveraging Google OAuth and WhatsApp linking. In response, WhatsApp is introducing a new 'Scam Alert' feature that uses an on-device machine learning model to flag potential scam messages. As no specific CVE vulnerabilities are provided for this reporting period, defenders should focus on user awareness training regarding these novel social engineering attacks, routinely auditing active 'Linked devices', and enabling the new security features.

Azərbaycanca: Hesabatlarımızda WhatsApp əsasən istifadəçi hesablarını hədəf alan fırıldaqçılıq və kibercasusluq kontekstində görünür. Əsas diqqət mərkəzində 'Bağlı Cihazlar' funksiyasından sui-istifadə edərək parol tələb etmədən hesabları ələ keçirən yeni dələduzluq metodu və Rusiya ilə əlaqəli olduğu güman edilən qrupların Google OAuth və WhatsApp hesab əlaqələndirməsindən istifadə edərək həyata keçirdiyi hədəfli kibercasusluq kampaniyaları dayanır. Buna cavab olaraq, WhatsApp cihaz üzərində işləyən maşın öyrənmə modeli vasitəsilə potensial fırıldaq mesajlarını bayraq edən yeni 'Scam Alert' funksiyasını təqdim edir. Bu hesabat dövrü üçün spesifik CVE zəiflikləri təqdim edilmədiyindən, müdafiəçilər diqqətlərini istifadəçiləri yeni nəsil sosial mühəndislik hücumları barədə məlumatlandırmağa, 'Bağlı Cihazlar' bölməsini mütəmadi yoxlamağa və yeni təhlükəsizlik funksiyalarının aktiv edilməsinə yönəltməlidirlər.

This hub is built from skopnix's own reporting on WhatsApp: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.