First published: Thu Sep 03 2020(Updated: )
A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have caused the recipient of a sticker message containing deliberately malformed data to load an image from a sender-controlled URL without user interaction.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Whatsapp Whatsapp | <2.20.11 | |
Whatsapp Whatsapp Business | <2.20.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-1890.
The severity level of CVE-2020-1890 is high.
WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 are affected.
CVE-2020-1890 is a URL validation issue that can cause the recipient of a sticker message to load an image from a sender-controlled URL without user interaction.
To fix CVE-2020-1890, update WhatsApp for Android to version 2.20.11 or later and WhatsApp Business for Android to version 2.20.2 or later.