← All CVEs

CVE-2019-3568

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-19Remediation due 2022-05-10

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

9.8
CVSS
30.1%
EPSS (exploit prob.)
98th
EPSS percentile
2019-05-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122CWE-787

Affected products

VendorProductAffected versions
whatsappwhatsapp< 2.18.15
whatsappwhatsapp< 2.18.348
whatsappwhatsapp< 2.19.51
whatsappwhatsapp< 2.19.134
whatsappwhatsapp_business< 2.19.44
whatsappwhatsapp_business< 2.19.51

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-3568