PT-2019-11021 · Facebook · Whatsapp For Android+1

Published

2019-06-14

·

Updated

2025-09-03

·

CVE-2018-6349

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WhatsApp for Android versions prior to 2.18.248 WhatsApp Business for Android versions prior to 2.18.132
Description: A missing size check when parsing a sender-provided packet allowed for a stack-based overflow, which occurs when receiving calls.
Recommendations: For WhatsApp for Android versions prior to 2.18.248, update to version 2.18.248 or later. For WhatsApp Business for Android versions prior to 2.18.132, update to version 2.18.132 or later.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6349

Affected Products

Whatsapp Business For Android
Whatsapp For Android