VYPR
Unrated severityNVD Advisory· Published Sep 27, 2019· Updated Aug 4, 2024

CVE-2019-11927

CVE-2019-11927

Description

An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on the heap via specially-crafted EXIF tags in WEBP images. This issue affects WhatsApp for Android before version 2.19.143 and WhatsApp for iOS before version 2.19.100.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An integer overflow in WhatsApp's media parsing allows remote code execution via a crafted WEBP image with malicious EXIF tags.

Vulnerability

An integer overflow vulnerability exists in the media parsing libraries of WhatsApp for Android and iOS when processing EXIF tags in WEBP images. This flaw allows a remote attacker to trigger an out-of-bounds write on the heap. Affected versions are WhatsApp for Android before version 2.19.143 and WhatsApp for iOS before version 2.19.100. [1]

Exploitation

An attacker can exploit this vulnerability by sending a specially-crafted WEBP image containing malicious EXIF tags to a victim via WhatsApp. No authentication is required beyond the victim receiving the message. The integer overflow occurs during parsing, leading to a heap buffer overflow that the attacker can control to achieve arbitrary code execution.

Impact

Successful exploitation enables a remote attacker to execute arbitrary code on the victim's device with the privileges of the WhatsApp application. This could result in full compromise of the messaging app and potentially the entire device, including access to sensitive data.

Mitigation

WhatsApp has released fixed versions: Android 2.19.143 and iOS 2.19.100. Users should update to these versions or later to mitigate the vulnerability. No workaround is available. [1]

References
  1. Facebook

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.