CVE Database
/

CVE-2019-3568

Back to search

CVE-2019-3568

Published: May 14, 2019

Modified: Oct 21, 2025

PUBLISHED

Description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

VendorProductVersions

Facebook

WhatsApp for Android

affected
2.19.134
affected
unspecified - < 2.19.134

Facebook

WhatsApp Business for Android

affected
2.19.44
affected
unspecified - < 2.19.134

Facebook

WhatsApp for iOS

affected
2.19.51
affected
unspecified - < 2.19.51

Facebook

WhatsApp Business for iOS

affected
2.19.51
affected
unspecified - < 2.19.51

Facebook

WhatsApp for Windows Phone

affected
2.18.348
affected
unspecified - < 2.18.348

Facebook

WhatsApp for Tizen

affected
2.18.15
affected
unspecified - < 2.18.15

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now