← Back

CVE-2019-3568

nvd nist
Published: May 14, 2019Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

Affected (6)

2 products
Whatsapp
Whatsapp Business
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Whatsapp
Before 2.19.134
Before 2.19.51
Before 2.18.15
Before 2.18.348
Whatsapp
Before 2.19.44
Before 2.19.51

References (5)

Source: cve-assign@fb.com
Broken LinkThird Party AdvisoryVDB Entry
Source: cve-assign@fb.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.