← Vulnerability feed

Vulnerability record · CVE-2022-36934 · published 22 September 2022

CVE-2022-36934: Whatsapp heap-based buffer overflow vulnerability

Whatsapp · Whatsapp

An integer overflow in WhatsApp could result in remote code execution in an established video call.

9.8 CVSS 3.1 Critical EPSS 2.4% · top 16.3% CWE-122 · Heap-based buffer overflowCWE-190 · Integer overflow
9.8CVSS 3.1 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36934 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3568WhatsApp VOIP stack heap buffer overflow allows remote code executionA heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number,…KEVEPSS 30%analysed8.2CVE-2019-18426WhatsApp Desktop link preview XSS and local file readWhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. …KEVEPSS 68%analysed5.4CVE-2025-55177WhatsApp iOS and Mac linked-device sync authorization flawWhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated…KEVEPSS 4.3%analysed9.8CVE-2021-24042Whatsapp heap-based buffer overflow vulnerabilityThe calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, W…EPSS 1.2%9.8CVE-2021-24041Whatsapp heap-based buffer overflow vulnerabilityA missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowe…EPSS 1.4%9.8CVE-2021-24026Whatsapp out-of-bounds write vulnerabilityA missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android …EPSS 1.4%9.8CVE-2020-1909Whatsapp use after free vulnerabilityA use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in …EPSS 2.3%9.8CVE-2020-1907Whatsapp out-of-bounds write vulnerabilityA stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2022-36934), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.