In light of WhatsApp’s widespread usage for personal and professional communication, CERT-In has stressed the importance of prompt action
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity advisory for users of WhatsApp Desktop on Windows, warning of a serious security vulnerability that could allow attackers to execute arbitrary code or launch spoofing attacks. The flaw, if exploited, could compromise a user’s system, leading to potential data theft or unauthorised access.
According to CERT-In, the vulnerability affects versions of WhatsApp Desktop for Windows earlier than 2.2450.6. The problem stems from a misconfiguration between MIME type and file extension validation, which results in improper handling of attachments within the application. This creates a situation where malicious files, when opened manually through WhatsApp, could trigger unintended code execution or allow an attacker to spoof system responses.
Classified under CVE-2025-30401, the flaw has been deemed “high” in severity due to the possible implications, including remote code execution or full system compromise. CERT-In has highlighted that attackers could potentially exploit this vulnerability by sending specially crafted attachments to victims through WhatsApp. If the user opens such an attachment, it may grant the attacker access to sensitive data or control over the affected machine.
In light of WhatsApp’s widespread usage for personal and professional communication, CERT-In has stressed the importance of prompt action. Users are strongly advised to verify the version of their WhatsApp Desktop app and update it to the latest build without delay. WhatsApp has already released a patch addressing the issue and has published a corresponding security advisory on its official website: https://www.whatsapp.com/security/advisories/2025.
Beyond the technical fix, CERT-In’s advisory serves as a reminder of the broader risks posed by software misconfigurations, especially in applications used across millions of systems globally. The agency urges users to practise caution when dealing with attachments, even those appearing to come from familiar contacts. Files received over messaging platforms should not be opened unless their source and content can be verified.
Cybersecurity experts consistently recommend users adopt basic digital hygiene practices to mitigate such threats. These include keeping software and applications up to date, enabling automatic updates where possible, and avoiding interaction with suspicious files or links. Additionally, implementing endpoint protection solutions and restricting administrative privileges on systems can help limit the impact of any potential compromise.
In recent years, desktop messaging clients have emerged as an attractive target for cybercriminals due to their integration with file systems and wider user base. With more professionals using these tools for work-related communication, vulnerabilities such as CVE-2025-30401 serve as a critical reminder of the need for regular security assessments and timely patching.
As attackers increasingly rely on social engineering and file-based exploits, staying ahead requires not only robust software development practices but also heightened user awareness. “Any software that interacts with attachments or executes file-based actions can be a target,” said a senior CERT-In official. “It is vital that users remain cautious and apply updates as soon as they are available.”
For WhatsApp Desktop users, the immediate priority is clear: update the application to version 2.2450.6 or later to ensure protection against this vulnerability. Following best practices and staying informed about emerging threats can make a significant difference in safeguarding digital communications and data.

