Junglewise Threat Intelligence

CVE-2019-3568: WhatsApp VOIP Stack Buffer Overflow Vulnerability

CVE-2019-3568 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-19

Technologies: WhatsApp for iOS, Meta Platforms WhatsApp. Vendors: Meta Platforms.

Executive brief

A buffer overflow vulnerability in the WhatsApp VOIP stack allows remote code execution via a specially crafted series of RTCP packets. An attacker can trigger the flaw by sending these packets to a target phone number without requiring user interaction.

Affected products

  • WhatsApp WhatsApp for Android prior to v2.19.134
  • WhatsApp WhatsApp Business for Android prior to v2.19.44
  • WhatsApp WhatsApp for iOS prior to v2.19.51
  • WhatsApp WhatsApp Business for iOS prior to v2.19.51
  • WhatsApp WhatsApp for Windows Phone prior to v2.18.348
  • WhatsApp WhatsApp for Tizen prior to v2.18.15

Timeline

  • 2019-05-14: disclosed: NVD Published Date
  • 2022-04-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-19: exploited: Reported as exploited in the wild

Related threats