CVE-2018-6349
Description
When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects WhatsApp for Android prior to 2.18.248 and WhatsApp Business for Android prior to 2.18.132.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A missing size check in WhatsApp for Android's call handling leads to a stack-based buffer overflow, enabling remote code execution.
Vulnerability
A stack-based buffer overflow exists in WhatsApp for Android and WhatsApp Business for Android when processing a sender-provided packet during call setup. The flaw stems from a missing size check in the packet parsing logic, allowing an attacker to write beyond the bounds of a stack buffer. This affects WhatsApp for Android versions prior to 2.18.248 and WhatsApp Business for Android versions prior to 2.18.132 [1].
Exploitation
An attacker can exploit this vulnerability by initiating a call to a target device and sending a specially crafted packet. No authentication or user interaction beyond answering the call is required. The attacker must be able to send network packets to the victim's device, typically over the internet via WhatsApp's infrastructure. The crafted packet triggers the overflow during parsing.
Impact
Successful exploitation allows an attacker to execute arbitrary code on the victim's device with the privileges of the WhatsApp application. This can lead to full compromise of the device, including access to messages, contacts, and other sensitive data. The vulnerability is remotely exploitable without prior access.
Mitigation
The issue is fixed in WhatsApp for Android version 2.18.248 and WhatsApp Business for Android version 2.18.132. Users should update their applications to the latest version from the Google Play Store or other official sources. No workarounds are available for unpatched versions [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3<2.18.248+ 2 more
- (no CPE)range: <2.18.248
- (no CPE)range: 2.18.132
- (no CPE)range: 2.18.248
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/108804mitrevdb-entryx_refsource_BID
- www.facebook.com/security/advisories/cve-2018-6349/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.