Stack Overflow Vulnerability in WhatsApp and WhatsApp Business on Android
CVE-2018-6339

9.8CRITICAL

Key Information:

Vendor

Facebook

Vendor
CVE Published:
14 June 2019

What is CVE-2018-6339?

An off-by-one error in the stack allocation during call handling in WhatsApp for Android can lead to a stack overflow, enabling potential arbitrary code execution. This vulnerability impacts versions starting from 2.18.180 for WhatsApp and from v2.18.103 for WhatsApp Business. It has been addressed in version 2.18.295 for WhatsApp and in version 2.18.150 for WhatsApp Business, emphasizing the importance of prompt updates to safeguard user data.

Affected Version(s)

WhatsApp Business for Android 2.18.150

WhatsApp Business for Android 2.18.103

WhatsApp for Android 2.18.295

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.