← Vulnerability feed

Vulnerability record · CVE-2019-11932 · published 3 October 2019

CVE-2019-11932: Whatsapp double free vulnerability

Whatsapp · Whatsapp

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

8.8 CVSS 3.1 High EPSS 45% · top 1.3% CWE-415 · Double free
8.8CVSS 3.1 base score, v2 6.8
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2019/Nov/27 Mailing ListThird Party Advisory
https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/ ExploitThird Party Advisory
https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263 Third Party Advisory
https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20 PatchThird Party Advisory
https://github.com/koral--/android-gif-drawable/pull/673 Third Party Advisory
https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9 Third Party Advisory
https://www.facebook.com/security/advisories/cve-2019-11932 Third Party Advisory
http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2019/Nov/27 Mailing ListThird Party Advisory
https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/ ExploitThird Party Advisory
https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263 Third Party Advisory
https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20 PatchThird Party Advisory
https://github.com/koral--/android-gif-drawable/pull/673 Third Party Advisory
https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9 Third Party Advisory
https://www.facebook.com/security/advisories/cve-2019-11932 Third Party Advisory

Track CVE-2019-11932 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3568WhatsApp VOIP stack heap buffer overflow allows remote code executionA heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number,…KEVEPSS 30%analysed8.2CVE-2019-18426WhatsApp Desktop link preview XSS and local file readWhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. …KEVEPSS 68%analysed5.4CVE-2025-55177WhatsApp iOS and Mac linked-device sync authorization flawWhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated…KEVEPSS 4.3%analysed9.8CVE-2022-36934Whatsapp heap-based buffer overflow vulnerabilityAn integer overflow in WhatsApp could result in remote code execution in an established video call.EPSS 2.4%9.8CVE-2021-24042Whatsapp heap-based buffer overflow vulnerabilityThe calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, W…EPSS 1.2%9.8CVE-2021-24041Whatsapp heap-based buffer overflow vulnerabilityA missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowe…EPSS 1.4%9.8CVE-2021-24026Whatsapp out-of-bounds write vulnerabilityA missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android …EPSS 1.4%9.8CVE-2020-1909Whatsapp use after free vulnerabilityA use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2019-11932), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.