Executive brief
A buffer overflow vulnerability in the WhatsApp VOIP stack allows remote code execution via a specially crafted series of RTCP packets. An attacker can trigger the flaw by sending these packets to a target phone number without requiring user interaction.
Affected products
- WhatsApp WhatsApp for Android prior to v2.19.134
- WhatsApp WhatsApp Business for Android prior to v2.19.44
- WhatsApp WhatsApp for iOS prior to v2.19.51
- WhatsApp WhatsApp Business for iOS prior to v2.19.51
- WhatsApp WhatsApp for Windows Phone prior to v2.18.348
- WhatsApp WhatsApp for Tizen prior to v2.18.15
Timeline
- 2019-05-14: disclosed: NVD Published Date
- 2022-04-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-19: exploited: Reported as exploited in the wild