Stack Overflow Vulnerability in WhatsApp and WhatsApp Business for Android and iOS
CVE-2020-1907

9.8CRITICAL

Key Information:

What is CVE-2020-1907?

A stack overflow vulnerability exists in WhatsApp and WhatsApp Business applications across various platforms, allowing arbitrary code execution when the applications improperly parse RTP Extension headers. This flaw affects versions prior to specified releases on both Android and iOS platforms, posing potential risks to user data and application integrity.

Affected Version(s)

WhatsApp Business for Android 2.20.196.12

WhatsApp Business for Android < 2.20.196.12

WhatsApp Business for iOS 2.20.90

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-1907 : Stack Overflow Vulnerability in WhatsApp and WhatsApp Business for Android and iOS