VYPR
Critical severity9.8CISA KEVNVD Advisory· Published May 14, 2019· Updated Jun 17, 2026

CVE-2019-3568

CVE-2019-3568

Description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • Whatsapp/Whatsapp5 versions
    cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*+ 4 more
    • cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*range: <2.19.134
    • cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*range: <2.19.51
    • cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:tizen:*:*range: <2.18.15
    • cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows_phone:*:*range: <2.18.348
    • (no CPE)range: <2.19.134
  • cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*range: <2.19.44
    • cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*range: <2.19.51
    • (no CPE)range: <2.19.44
  • Facebook/WhatsAppllm-create
    Range: <2.19.134
  • Facebook/WhatsApp for Androidcpe-rescue2 versions
    2.19.44+ 1 more
    • (no CPE)range: 2.19.44
    • (no CPE)range: 2.19.134
  • Range: 2.19.51
  • Facebook/WhatsApp for iPhonecpe-rescue2 versions
    2.19.51+ 1 more
    • (no CPE)range: 2.19.51
    • (no CPE)range: 2.18.348
  • Facebook/WhatsApp for Tizenv5
    Range: 2.18.15

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.