CVE Database
/

CVE-2020-1905

Back to search

CVE-2020-1905

Published: Oct 6, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.

VendorProductVersions

Facebook

WhatsApp for Android

affected
2.20.185
affected
unspecified - < 2.20.185

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now