PT-2020-15159 · Whatsapp · Whatsapp For Android

Published

2020-10-06

·

Updated

2020-10-13

·

CVE-2020-1905

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WhatsApp for Android versions prior to 2.20.185
Description A issue exists where Media ContentProvider URIs used for opening attachments in other apps were generated sequentially, which could have allowed a malicious third party app to guess the URIs for previously opened attachments until the opener app is terminated.
Recommendations For versions prior to 2.20.185, update to version 2.20.185 or later to resolve the issue.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1905

Affected Products

Whatsapp For Android