CVE-2019-3568

Confirmed PUBLISHED

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target...

Facebook · WhatsApp for Android, WhatsApp Business for Android, WhatsApp for iOS, WhatsApp Business for iOS, WhatsApp for Windows Phone, WhatsApp for Tizen
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

cisa ios windows android
CVE Published
May 14, 2019
Exploitation Reported
Apr 19, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Facebook
WhatsApp for Android

2.19.134

Affected
Facebook
WhatsApp for Android

unspecified to < 2.19.134

Affected
Facebook
WhatsApp Business for Android

2.19.44

Affected
Facebook
WhatsApp Business for Android

unspecified to < 2.19.134

Affected
Facebook
WhatsApp for iOS

2.19.51

Affected
Facebook
WhatsApp for iOS

unspecified to < 2.19.51

Affected
Facebook
WhatsApp Business for iOS

2.19.51

Affected
Facebook
WhatsApp Business for iOS

unspecified to < 2.19.51

Affected
Facebook
WhatsApp for Windows Phone

2.18.348

Affected
Facebook
WhatsApp for Windows Phone

unspecified to < 2.18.348

Affected
Facebook
WhatsApp for Tizen

2.18.15

Affected
Facebook
WhatsApp for Tizen

unspecified to < 2.18.15

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.