ZeroHour

CVE-2019-3568

KEVmass

Buffer Overflow RCE in WhatsApp VoIP Stack via Crafted RTCP Packets

CISA: WhatsApp VOIP Stack Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
30%p98
Published
()
KEV added
AI analysis

A buffer overflow (CWE-122) in the VoIP telephony stack of WhatsApp allowed a remote attacker to achieve remote code execution on a target device by sending a specially crafted series of RTCP packets to the victim's phone number. Because the flaw resided in the call-handling stack of the core app, an attacker who could reach the target's phone number over the network could gain arbitrary code execution on the device. All WhatsApp users at the time of disclosure were potentially exposed, since the vulnerable component shipped in the mainstream Meta Platforms (then Facebook) product rather than an optional add-on. The vulnerability was added to CISA's Known Exploited Vulnerability catalog on 2022-04-19, indicating confirmed real-world exploitation, and its EPSS score of 39.2% (99th percentile) signals a high likelihood of continued exploitation; no public proof-of-concept is known. It was remediated in vendor updates issued in 2019 and is widely associated with targeted espionage use (notably Pegasus spyware deployments).

What to do: Update WhatsApp on all mobile devices to the latest vendor release, per the CISA KEV required action; inventory your mobile fleet for outdated 2019-era builds and verify current app versions. Prioritize high-value targets (executives, journalists, government personnel) given the vulnerability's confirmed in-the-wild exploitation in espionage campaigns. No public PoC is known, but the flaw is remotely exploitable via network packets to a phone number, so treat patching as urgent.

Affected
Meta Platforms WhatsApp
Estimated exposure
mass≈1.5–2 billion users (effectively the entire global WhatsApp user base at the time of disclosure) — WhatsApp's publicly reported user base was roughly 1.5 billion monthly users in 2019 and has since exceeded 2 billion, and the vulnerable VoIP stack was part of the core app on every installation.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

CISA Known Exploited Vulnerability
Affected
Meta Platforms WhatsApp
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
whatsapp
Products
whatsapp, whatsapp business
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news