Unrated severityCISA KEVNVD Advisory· Published May 14, 2019· Updated Oct 21, 2025
CVE-2019-3568
CVE-2019-3568
Description
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
Affected products
6- Facebook/WhatsApp for Androidv5Range: 2.19.134
- Facebook/WhatsApp Business for Androidv5Range: 2.19.44
- Facebook/WhatsApp for iOSv5Range: 2.19.51
- Facebook/WhatsApp Business for iOSv5Range: 2.19.51
- Facebook/WhatsApp for Windows Phonev5Range: 2.18.348
- Facebook/WhatsApp for Tizenv5Range: 2.18.15
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/108329mitrevdb-entryx_refsource_BID
- www.facebook.com/security/advisories/cve-2019-3568mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.