MIME The Attachments You Open In WhatsApp For Windows

Source: The Register MIME The Attachments You Open In WhatsApp For Windows

The Meta Behind The WhatsApp Doc-tored Attachments

If you have fallen under the Zuck’s influence and use WhatsApp for Windows you might want to stop, or at least stop opening attachments until you are positive you’ve updated to at least version 2.2450.6.  There is a rather nasty bug in previous versions which allows code execution to be triggered when you open a doctored attachment that was sent to you.  The attachment could be anything from a document to a JPEG, and since most users tend to click on anything they are sent there is a good chance this is going to hit people you know, if not yourself.

The flaw comes about thanks to WhatsApp using MIME to identify what type of file was sent, and theoretically which app to use to open it.  The problem is that MIME can lie, and what you see as a perfectly innocent image, or even not so innocent, is actually an EXE file.  You won’t see any indication of that trickery, as WhatsApp believes the MIME metadata and displays the attachment as whatever MIME tells says it is.  Howsoever when you click the attachment, the actual file type is registered with the OS and the EXE is launched.

Always be careful clicking attachments; even more so if your tendency is not to regularly check for app updates.

The spoofing flaw, tracked as CVE-2025-30401, affects all versions of WhatsApp Desktop for Windows prior to 2.2450.6, and stems from a bug in how the app handles file attachments.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!