<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nday on Numb3rs' blog</title><link>https://numb3rs.re/tags/nday/</link><description>Recent content in Nday on Numb3rs' blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 05 Oct 2026 14:12:09 -0700</lastBuildDate><atom:link href="https://numb3rs.re/tags/nday/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-23866: Finding a Whatsapp NDay</title><link>https://numb3rs.re/posts/cve-2026-23866-finding-a-whatsapp-nday/</link><pubDate>Mon, 05 Oct 2026 14:12:09 -0700</pubDate><guid>https://numb3rs.re/posts/cve-2026-23866-finding-a-whatsapp-nday/</guid><description>On May 1 2026, CVE-2026-23866 was published, the vulnerability reportedly allows a malicious attacker to force a victim into loading an arbitrary URL and thus leaking important information (headers, ip address, &amp;hellip;). It&amp;rsquo;s a low grade vulnerability but I&amp;rsquo;ve never worked on Whatsapp so I figured it&amp;rsquo;d be interesting to take a look at it.
The only informations I will be using are those publicly available on the NIST website .</description></item></channel></rss>