CVE-2019-3568
WhatsApp VOIP Stack Buffer Overflow Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2019-3568
Description
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| WhatsApp for Android | 2.19.134 unspecified to <2.19.134 | |
| WhatsApp Business for Android | 2.19.44 unspecified to <2.19.134 | |
| WhatsApp for iOS | 2.19.51 unspecified to <2.19.51 | |
| WhatsApp Business for iOS | 2.19.51 unspecified to <2.19.51 | |
| WhatsApp for Windows Phone | 2.18.348 unspecified to <2.18.348 | |
| WhatsApp for Tizen | 2.18.15 unspecified to <2.18.15 |
References
2 LinksRecord Details
More from Facebook
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.