CVE-2019-3568 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 30.1% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-10.
Description
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 30.08% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-122 |
| On CISA KEV | yes — remediate by 2022-05-10 |
| Public exploit | none known |
| Published | 2019-05-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | WhatsApp VOIP Stack Buffer Overflow Vulnerability |
|---|---|
| Added | 2022-04-19 |
| Due | 2022-05-10 |
| Vendor / product | Meta Platforms / WhatsApp |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| whatsapp business |
References
→ the Explorer · watch your stack · NVD