VYPR
Unrated severityNVD Advisory· Published Jun 14, 2019· Updated Aug 5, 2024

CVE-2018-20655

CVE-2018-20655

Description

When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects WhatsApp for iOS prior to v2.18.90.24 and WhatsApp Business for iOS prior to v2.18.90.24.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based overflow in WhatsApp for iOS due to missing size check when parsing a sender-provided packet; fixed in v2.18.90.24.

Vulnerability

A missing size check when parsing a sender-provided packet during WhatsApp calls allows a stack-based buffer overflow. This affects WhatsApp for iOS prior to v2.18.90.24 and WhatsApp Business for iOS prior to v2.18.90.24 [1].

Exploitation

An attacker can send a crafted packet to a victim during a WhatsApp call. No authentication is required beyond initiating a call; the vulnerability is triggered when the receiver parses the malicious packet.

Impact

Successful exploitation could allow an attacker to achieve arbitrary code execution on the victim's device, potentially leading to full compromise of the WhatsApp application and device data.

Mitigation

Update to WhatsApp for iOS v2.18.90.24 or later, or WhatsApp Business for iOS v2.18.90.24 or later [1]. No workaround is available.

References
  1. Facebook

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.