← Vulnerability feed

Vulnerability record · CVE-2019-3568 · published 14 May 2019

CVE-2019-3568: WhatsApp VOIP stack heap buffer overflow allows remote code execution

Whatsapp · Whatsapp

A heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number, leading to remote code execution. The flaw affects WhatsApp and WhatsApp Business across Android, iOS, Windows Phone and Tizen before their respective fixed versions. Because it is reachable over the network with no authentication or user action, it is a serious pre-patch risk for unpatched clients.

9.8 CVSS 3.1 Critical CISA KEV since 19 Apr 2022 EPSS 30% · top 1.8% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
30%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, remote code execution impact, and confirmed KEV listing make this a top remediation priority.

What it is

A heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number, leading to remote code execution. The flaw affects WhatsApp and WhatsApp Business across Android, iOS, Windows Phone and Tizen before their respective fixed versions. Because it is reachable over the network with no authentication or user action, it is a serious pre-patch risk for unpatched clients.

Impact

An attacker can execute code on the target device remotely, giving full control of the handset and its data without any user interaction.

Attack surface

Reached over the network by sending crafted RTCP packets to a target phone number through the VOIP stack; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Listed in CISA KEV since 2022-04-19 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.30076 (98th percentile), indicating observed exploitation activity. No ransomware campaign use is documented.

What to do

  • Update WhatsApp and WhatsApp Business to the fixed versions: Android 2.19.134 / Business 2.19.44, iOS 2.19.51 / Business 2.19.51, Windows Phone 2.18.348, Tizen 2.18.15 or later.
  • Inventory all endpoints running WhatsApp or WhatsApp Business, including older Windows Phone and Tizen devices that may be out of support.
  • Where patching is not immediately possible, restrict or disable the affected VOIP calling functionality until the client is updated.
  • Track KEV remediation deadlines and verify update compliance across managed mobile fleets.
  • Monitor vendor advisories for any further guidance on the VOIP stack.

Detection

  • Check installed WhatsApp and WhatsApp Business versions against the fixed version list on managed devices.
  • Alert on unexpected crashes or restarts of the WhatsApp process, which may indicate exploitation attempts.
  • Monitor network traffic for anomalous RTCP packet patterns directed at WhatsApp VOIP endpoints.
  • Review mobile threat defense or EDR telemetry for code execution or memory corruption indicators in the WhatsApp process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-3568 to the Known Exploited Vulnerabilities catalog on 19 April 2022 as "WhatsApp VOIP Stack Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3568 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2019-18426WhatsApp Desktop link preview XSS and local file readWhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. …KEVEPSS 68%analysed5.4CVE-2025-55177WhatsApp iOS and Mac linked-device sync authorization flawWhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated…KEVEPSS 4.3%analysed9.8CVE-2022-36934Whatsapp heap-based buffer overflow vulnerabilityAn integer overflow in WhatsApp could result in remote code execution in an established video call.EPSS 2.4%9.8CVE-2021-24042Whatsapp heap-based buffer overflow vulnerabilityThe calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, W…EPSS 1.2%9.8CVE-2021-24041Whatsapp heap-based buffer overflow vulnerabilityA missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowe…EPSS 1.4%9.8CVE-2021-24026Whatsapp out-of-bounds write vulnerabilityA missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android …EPSS 1.4%9.8CVE-2020-1909Whatsapp use after free vulnerabilityA use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in …EPSS 2.3%9.8CVE-2020-1907Whatsapp out-of-bounds write vulnerabilityA stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2019-3568), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.