CVE-2025-30401

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Apr 5, 2025
Updated: Apr 9, 2025

Summary

CVE-2025-30401 is a spoofing vulnerability affecting WhatsApp for Windows before version 2.2450.6. The issue lies in the way attachments are handled: MIME type is used to determine how an attachment is displayed, but the file opening handler is chosen based on the filename extension. A maliciously crafted attachment with a misleading filename and MIME type could trick the user into opening a file that contains arbitrary code, leading to potential security risks. No evidence of exploitation in the wild has been reported.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share