WhatsApp users on Windows PCs advised caution following Cert-In warning

Cert-In stated that the vulnerability in WhatsApp for Windows PC could be exploited by bad actors that may enable them to run harmful code on the victim's device, potentially compromising the system

WhatsApp
WhatsApp
Aashish Kumar Shrivastava New Delhi
2 min read Last Updated : Apr 14 2025 | 11:08 AM IST
The Indian Computer Emergency Response Team (CERT-In) has issued a “high-severity” warning for WhatsApp desktop for Windows users. As per CERT-In, there is a vulnerability that could allow attackers to execute arbitrary code or launch spoofing attacks, potentially compromising system security.
 

Who is affected

 
This vulnerability affects users using WhatsApp desktop for Windows versions 2.2450.6 or older. If a user is using this version or any version prior to this then they are at high risk of being cyberattacked.
 
If affected, users might unknowingly give unauthorised access of their devices to cybercriminals. Hackers will be in a comfortable position to steal the data available on the system.
 

What’s the risk

 
High risk of unauthorised access
Data theft
Gain control of affected windows
 ALSO READ | CERT-In flags security flaws in iPhones, iPads, Macs with outdated software 

Where does it stem from

 
This vulnerability stems from a misalignment between the MIME type and the way file attachments are handled. An attacker can take advantage of this flaw by creating a specially crafted file that, when manually opened in WhatsApp, could trigger the execution of malicious code.
 
If exploited successfully, the vulnerability may enable the attacker to run harmful code on the victim’s device, potentially compromising the targeted system.
 

How to keep yourself protected

 
The first and foremost thing that users should do in order to safeguard themselves and their data against these cyberattacks is to update their WhatsApp Desktop for Windows to the latest version as soon as possible. Running an older version will always make them prone to such attacks.
 
Secondly, users should invest in some decent antivirus software which will regularly scan their system and alerts if it detects any malicious software.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :whatsappWhatsApp in IndiaCyberattacks

First Published: Apr 14 2025 | 11:08 AM IST

Next Story