CISA Known Exploited Vulnerability

CVE-2019-3568

Meta Platforms · WhatsApp

WhatsApp VOIP Stack Buffer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-122
Ransomware Unknown

CISA description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

Required action

Apply updates per vendor instructions.