peter bassill · operator
$ cve CVE-2019-3568 JSON

CVE-2019-3568 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 30.1% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-10.

Description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS30.08% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-122
On CISA KEVyes — remediate by 2022-05-10
Public exploitnone known
Published2019-05-14
Last modified2026-06-17

CISA KEV

NameWhatsApp VOIP Stack Buffer Overflow Vulnerability
Added2022-04-19
Due2022-05-10
Vendor / productMeta Platforms / WhatsApp
Ransomware usenone reported

Affected (2)

VendorProduct
whatsappwhatsapp
whatsappwhatsapp business

References

→ the Explorer  ·  watch your stack  ·  NVD