Stack Overflow Vulnerability in WhatsApp and WhatsApp Business for Android and iOS
CVE-2020-1907
9.8CRITICAL
What is CVE-2020-1907?
A stack overflow vulnerability exists in WhatsApp and WhatsApp Business applications across various platforms, allowing arbitrary code execution when the applications improperly parse RTP Extension headers. This flaw affects versions prior to specified releases on both Android and iOS platforms, posing potential risks to user data and application integrity.
Affected Version(s)
WhatsApp Business for Android 2.20.196.12
WhatsApp Business for Android < 2.20.196.12
WhatsApp Business for iOS 2.20.90
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved