CVE-2020-1890: Input Validation
A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have caused the recipient of a sticker message containing deliberately malformed data to load an image from a sender-controlled URL without user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-1890.
What is the severity level of CVE-2020-1890?
The severity level of CVE-2020-1890 is high.
Which software versions are affected by CVE-2020-1890?
WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 are affected.
What is the nature of CVE-2020-1890?
CVE-2020-1890 is a URL validation issue that can cause the recipient of a sticker message to load an image from a sender-controlled URL without user interaction.
How can I fix CVE-2020-1890?
To fix CVE-2020-1890, update WhatsApp for Android to version 2.20.11 or later and WhatsApp Business for Android to version 2.20.2 or later.