WhatsApp records
46 published records for vendor whatsapp.
Researcher profile
- Entered KEV
- 3 · 6.5%
- Weaponized
- 3 · 6.5%
- Pre-auth RCE
- 7
- With a fix record
- 17.4%
- Median publish → KEV
- 853 days
Recurring classes
- CWE-122 Heap-based Buffer Overflow6
- CWE-787 Out-of-bounds Write5
- CWE-121 Stack-based Buffer Overflow4
- CWE-125 Out-of-bounds Read2
- CWE-23 Relative Path Traversal2
- CWE-400 Uncontrolled Resource Consumption2
The weakness classes this vendor ships most often: where to look.
CWEAll records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
82Now | CVE-2019-18426Weaponized | A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-swhatsapp · whatsapp · CWE-79 | High8.2 | KEV | 67.9% | Jan 21, 2020 |
78This week | CVE-2019-3568Weaponized | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a whatsapp · whatsapp · CWE-122 | Critical9.8 | KEV | 30.1% | May 14, 2019 |
52Plan | CVE-2025-55177Weaponized | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25whatsapp · whatsapp · CWE-863 | Medium5.4 | KEV | 4.3% | Aug 29, 2025 |
48Plan | CVE-2019-11932Proof of concept | A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in Wwhatsapp · whatsapp · CWE-415 | High8.8 | — | 44.5% | Oct 3, 2019 |
41Plan | CVE-2020-1889No exploit | A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalawhatsapp · whatsapp desktop · CWE-265 | Critical10.0 | — | 4.8% | Sep 3, 2020 |
40Plan | CVE-2019-11933Proof of concept | A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remwhatsapp · whatsapp · CWE-119 | Critical9.8 | — | 4.1% | Oct 23, 2019 |
40Plan | CVE-2022-36934Proof of concept | An integer overflow in WhatsApp could result in remote code execution in an established video call.whatsapp · whatsapp · CWE-122 | Critical9.8 | — | 2.4% | Sep 22, 2022 |
40Plan | CVE-2020-1909No exploit | A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have reswhatsapp · whatsapp · CWE-416 | Critical9.8 | — | 2.3% | Nov 3, 2020 |
40Plan | CVE-2018-6349No exploit | When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflwhatsapp · whatsapp · CWE-121 | Critical9.8 | — | 2.2% | Jun 14, 2019 |
40Plan | CVE-2018-20655No exploit | When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow.whatsapp · whatsapp · CWE-121 | Critical9.8 | — | 2.2% | Jun 14, 2019 |
40Plan | CVE-2020-1907No exploit | A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior whatsapp · whatsapp · CWE-787 | Critical9.8 | — | 1.9% | Oct 6, 2020 |
40Plan | CVE-2018-6350No exploit | An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers.whatsapp · whatsapp · CWE-125 | Critical9.8 | — | 1.7% | Jun 14, 2019 |
39Monitor | CVE-2018-6339No exploit | When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in.whatsapp · whatsapp · CWE-121 | Critical9.8 | — | 1.5% | Jun 14, 2019 |
39Monitor | CVE-2020-1891No exploit | A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, Whwhatsapp · whatsapp · CWE-787 | Critical9.8 | — | 1.5% | Sep 3, 2020 |
39Monitor | CVE-2021-24026No exploit | A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business forwhatsapp · whatsapp · CWE-787 | Critical9.8 | — | 1.4% | Apr 6, 2021 |
39Monitor | CVE-2021-24041No exploit | A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could hawhatsapp · whatsapp · CWE-122 | Critical9.8 | — | 1.4% | Dec 7, 2021 |
39Monitor | CVE-2021-24042No exploit | The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.whatsapp · whatsapp · CWE-122 | Critical9.8 | — | 1.2% | Jan 4, 2022 |
36Monitor | CVE-2020-1894No exploit | A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone priorwhatsapp · whatsapp · CWE-787 | High8.8 | — | 1.8% | Sep 3, 2020 |
36Monitor | CVE-2021-24035No exploit | A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 whatsapp · whatsapp · CWE-23 | Critical9.1 | — | 1.1% | Jun 11, 2021 |
36Monitor | CVE-2021-24043No exploit | A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsAppwhatsapp · whatsapp · CWE-125 | Critical9.1 | — | 1.1% | Feb 2, 2022 |
35Monitor | CVE-2020-1886No exploit | A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have allowed an out-of-whatsapp · whatsapp · CWE-120 | High8.8 | — | 1.2% | Sep 3, 2020 |
33Monitor | CVE-2020-1910No exploit | A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed whatsapp · whatsapp · CWE-787 | High7.8 | — | 5.1% | Feb 2, 2021 |
32Monitor | CVE-2025-30401No exploit | A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file whatsapp · whatsapp · CWE-430 | Medium6.7 | — | 21.0% | Apr 5, 2025 |
31Monitor | CVE-2021-24027Proof of concept | A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third pwhatsapp · whatsapp · CWE-524 | High7.5 | — | 3.8% | Apr 6, 2021 |
31Monitor | CVE-2018-6344No exploit | A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established.whatsapp · whatsapp · CWE-122 | High7.5 | — | 1.9% | Dec 31, 2018 |
- CVE-2019-1842682Now
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-s
HighCVSS 8.2KEVWeaponizedEPSS 68%whatsapp · whatsappJan 21, 2020
- CVE-2019-356878This week
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a
CriticalCVSS 9.8KEVWeaponizedEPSS 30%whatsapp · whatsappMay 14, 2019
- CVE-2025-5517752Plan
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25
MediumCVSS 5.4KEVWeaponizedEPSS 4%whatsapp · whatsappAug 29, 2025
- CVE-2019-1193248Plan
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in W
HighCVSS 8.8Proof of conceptEPSS 45%whatsapp · whatsappOct 3, 2019
- CVE-2020-188941Plan
A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escala
CriticalCVSS 10.0No exploitEPSS 5%whatsapp · whatsapp desktopSep 3, 2020
- CVE-2019-1193340Plan
A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow rem
CriticalCVSS 9.8Proof of conceptEPSS 4%whatsapp · whatsappOct 23, 2019
- CVE-2022-3693440Plan
An integer overflow in WhatsApp could result in remote code execution in an established video call.
CriticalCVSS 9.8Proof of conceptEPSS 2%whatsapp · whatsappSep 22, 2022
- CVE-2020-190940Plan
A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have res
CriticalCVSS 9.8No exploitEPSS 2%whatsapp · whatsappNov 3, 2020
- CVE-2018-634940Plan
When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overfl
CriticalCVSS 9.8No exploitEPSS 2%whatsapp · whatsappJun 14, 2019
- CVE-2018-2065540Plan
When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow.
CriticalCVSS 9.8No exploitEPSS 2%whatsapp · whatsappJun 14, 2019
- CVE-2020-190740Plan
A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior
CriticalCVSS 9.8No exploitEPSS 2%whatsapp · whatsappOct 6, 2020
- CVE-2018-635040Plan
An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers.
CriticalCVSS 9.8No exploitEPSS 2%whatsapp · whatsappJun 14, 2019
- CVE-2018-633939Monitor
When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in.
CriticalCVSS 9.8No exploitEPSS 2%whatsapp · whatsappJun 14, 2019
- CVE-2020-189139Monitor
A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, Wh
CriticalCVSS 9.8No exploitEPSS 1%whatsapp · whatsappSep 3, 2020
- CVE-2021-2402639Monitor
A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for
CriticalCVSS 9.8No exploitEPSS 1%whatsapp · whatsappApr 6, 2021
- CVE-2021-2404139Monitor
A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could ha
CriticalCVSS 9.8No exploitEPSS 1%whatsapp · whatsappDec 7, 2021
- CVE-2021-2404239Monitor
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.
CriticalCVSS 9.8No exploitEPSS 1%whatsapp · whatsappJan 4, 2022
- CVE-2020-189436Monitor
A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior
HighCVSS 8.8No exploitEPSS 2%whatsapp · whatsappSep 3, 2020
- CVE-2021-2403536Monitor
A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13
CriticalCVSS 9.1No exploitEPSS 1%whatsapp · whatsappJun 11, 2021
- CVE-2021-2404336Monitor
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp
CriticalCVSS 9.1No exploitEPSS 1%whatsapp · whatsappFeb 2, 2022
- CVE-2020-188635Monitor
A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have allowed an out-of-
HighCVSS 8.8No exploitEPSS 1%whatsapp · whatsappSep 3, 2020
- CVE-2020-191033Monitor
A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed
HighCVSS 7.8No exploitEPSS 5%whatsapp · whatsappFeb 2, 2021
- CVE-2025-3040132Monitor
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file
MediumCVSS 6.7No exploitEPSS 21%whatsapp · whatsappApr 5, 2025
- CVE-2021-2402731Monitor
A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third p
HighCVSS 7.5Proof of conceptEPSS 4%whatsapp · whatsappApr 6, 2021
- CVE-2018-634431Monitor
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established.
HighCVSS 7.5No exploitEPSS 2%whatsapp · whatsappDec 31, 2018