Vulnerability record · CVE-2019-3568 · published 14 May 2019
CVE-2019-3568: WhatsApp VOIP stack heap buffer overflow allows remote code execution
Whatsapp · Whatsapp
A heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number, leading to remote code execution. The flaw affects WhatsApp and WhatsApp Business across Android, iOS, Windows Phone and Tizen before their respective fixed versions. Because it is reachable over the network with no authentication or user action, it is a serious pre-patch risk for unpatched clients.
Description
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, remote code execution impact, and confirmed KEV listing make this a top remediation priority.
What it is
A heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number, leading to remote code execution. The flaw affects WhatsApp and WhatsApp Business across Android, iOS, Windows Phone and Tizen before their respective fixed versions. Because it is reachable over the network with no authentication or user action, it is a serious pre-patch risk for unpatched clients.
Impact
An attacker can execute code on the target device remotely, giving full control of the handset and its data without any user interaction.
Attack surface
Reached over the network by sending crafted RTCP packets to a target phone number through the VOIP stack; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Listed in CISA KEV since 2022-04-19 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.30076 (98th percentile), indicating observed exploitation activity. No ransomware campaign use is documented.
What to do
- Update WhatsApp and WhatsApp Business to the fixed versions: Android 2.19.134 / Business 2.19.44, iOS 2.19.51 / Business 2.19.51, Windows Phone 2.18.348, Tizen 2.18.15 or later.
- Inventory all endpoints running WhatsApp or WhatsApp Business, including older Windows Phone and Tizen devices that may be out of support.
- Where patching is not immediately possible, restrict or disable the affected VOIP calling functionality until the client is updated.
- Track KEV remediation deadlines and verify update compliance across managed mobile fleets.
- Monitor vendor advisories for any further guidance on the VOIP stack.
Detection
- Check installed WhatsApp and WhatsApp Business versions against the fixed version list on managed devices.
- Alert on unexpected crashes or restarts of the WhatsApp process, which may indicate exploitation attempts.
- Monitor network traffic for anomalous RTCP packet patterns directed at WhatsApp VOIP endpoints.
- Review mobile threat defense or EDR telemetry for code execution or memory corruption indicators in the WhatsApp process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-3568 to the Known Exploited Vulnerabilities catalog on 19 April 2022 as "WhatsApp VOIP Stack Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/108329 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.facebook.com/security/advisories/cve-2019-3568 | Third Party Advisory |
| http://www.securityfocus.com/bid/108329 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.facebook.com/security/advisories/cve-2019-3568 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3568 | US Government Resource |
Track CVE-2019-3568 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-3568), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.