PT-2019-16615 · Facebook · Whatsapp For Android+1
Published
2019-05-10
·
Updated
2021-09-14
·
CVE-2019-3566
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WhatsApp for Android versions 2.19.52 through 2.19.103
WhatsApp Business for Android versions 2.19.22 through 2.19.38
Description
A bug in the messaging logic of WhatsApp for Android could allow a malicious individual who has taken over a user's account to recover previously sent messages. This would require the malicious individual to have independent knowledge of metadata for previous messages, which are not publicly available.
Recommendations
For WhatsApp for Android versions 2.19.52 through 2.19.103, update to a version outside of this range to resolve the issue.
For WhatsApp Business for Android versions 2.19.22 through 2.19.38, update to a version outside of this range to resolve the issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Whatsapp Business For Android
Whatsapp For Android