CVE-2019-11927
Description
An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on the heap via specially-crafted EXIF tags in WEBP images. This issue affects WhatsApp for Android before version 2.19.143 and WhatsApp for iOS before version 2.19.100.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An integer overflow in WhatsApp's media parsing allows remote code execution via a crafted WEBP image with malicious EXIF tags.
Vulnerability
An integer overflow vulnerability exists in the media parsing libraries of WhatsApp for Android and iOS when processing EXIF tags in WEBP images. This flaw allows a remote attacker to trigger an out-of-bounds write on the heap. Affected versions are WhatsApp for Android before version 2.19.143 and WhatsApp for iOS before version 2.19.100. [1]
Exploitation
An attacker can exploit this vulnerability by sending a specially-crafted WEBP image containing malicious EXIF tags to a victim via WhatsApp. No authentication is required beyond the victim receiving the message. The integer overflow occurs during parsing, leading to a heap buffer overflow that the attacker can control to achieve arbitrary code execution.
Impact
Successful exploitation enables a remote attacker to execute arbitrary code on the victim's device with the privileges of the WhatsApp application. This could result in full compromise of the messaging app and potentially the entire device, including access to sensitive data.
Mitigation
WhatsApp has released fixed versions: Android 2.19.143 and iOS 2.19.100. Users should update to these versions or later to mitigate the vulnerability. No workaround is available. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: before version 2.19.143
- Range: before version 2.19.100
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.facebook.com/security/advisories/cve-2019-11927mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.