Back

CVE-2019-3568

CRITICAL CISA KEV

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

Published: May 14, 2019 Modified: Jun 17, 2026
CWE-122 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
whatsapp whatsapp * < 2.18.15
whatsapp whatsapp * < 2.18.348
whatsapp whatsapp * < 2.19.51
whatsapp whatsapp * < 2.19.134
whatsapp whatsapp_business * < 2.19.44
whatsapp whatsapp_business * < 2.19.51

GitHub Security Advisory GHSA-cmw5-mmg8-r4fr

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 39.17%

Top 2% most likely to be exploited

Threat Score 80.9 / 100

CISA Known Exploited

Date Added: 2022-04-19
Due Date: 2022-05-10
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub