WhatsApp users are advised to review their settings and ensure they have the latest app version installed following the discovery of two security vulnerabilities in the messaging service. Security experts have identified issues related to media files and attachments handling, as well as a specific concern for Windows users.
While these vulnerabilities do not automatically infect devices, they could potentially be exploited by cybercriminals for social engineering attacks or combined with other vulnerabilities for more serious threats, as highlighted by Malwarebytes.
The flaws, known as CVE-2026-23866 and CVE-2026-23863, were uncovered through Meta’s Bug Bounty program. Although there is no evidence of real-world exploitation or phone infections at present, WhatsApp has released an update to address these vulnerabilities and strongly recommends users to review their settings for added security.
To safeguard against potential risks, users are urged to ensure their WhatsApp is fully updated. Android users can update the app through the Google Play Store, while iPhone users can do so via the App Store.
In a related development, some older Android devices may lose access to WhatsApp soon, as the messaging platform plans to discontinue support for devices running versions older than Android 6 starting September 8, 2026. Affected users might receive a notification indicating that WhatsApp will no longer function on their device.
Despite this change, the impact is expected to be minimal since Android 6 was released in 2015 and is no longer prevalent on modern smartphones.
