CVE-2025-55177
- EPSS 0.63%
- Veröffentlicht 29.08.2025 15:50:28
- Zuletzt bearbeitet 03.09.2025 14:03:49
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content...
CVE-2025-30401
- EPSS 0.06%
- Veröffentlicht 05.04.2025 11:47:54
- Zuletzt bearbeitet 09.04.2025 18:15:45
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused...
- EPSS 0.09%
- Veröffentlicht 04.10.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:47
A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
CVE-2023-38537
- EPSS 0.11%
- Veröffentlicht 04.10.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:47
A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
CVE-2022-27492
- EPSS 1.43%
- Veröffentlicht 23.09.2022 14:15:12
- Zuletzt bearbeitet 22.05.2025 19:15:29
An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.
CVE-2022-36934
- EPSS 11.36%
- Veröffentlicht 22.09.2022 22:15:09
- Zuletzt bearbeitet 24.09.2025 19:43:25
An integer overflow in WhatsApp could result in remote code execution in an established video call.
CVE-2020-20096
- EPSS 0.41%
- Veröffentlicht 23.03.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:50
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
CVE-2021-24043
- EPSS 0.57%
- Veröffentlicht 02.02.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:52:16
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed ...
CVE-2021-24042
- EPSS 0.5%
- Veröffentlicht 04.01.2022 19:15:14
- Zuletzt bearbeitet 22.05.2025 19:15:23
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop pr...
CVE-2021-24041
- EPSS 0.69%
- Veröffentlicht 07.12.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:52:15
A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image.