CVE-2020-1894: High severity whatsapp vulnerability
A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30 could have allowed arbitrary code execution when playing a specially crafted push to talk message.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-1894?
CVE-2020-1894 is a vulnerability in WhatsApp for Android and WhatsApp Business for Android that could allow arbitrary code execution when playing a specially crafted push to talk message.
What is the severity of CVE-2020-1894?
The severity of CVE-2020-1894 is high with a severity value of 8.8.
Which software versions are affected by CVE-2020-1894?
WhatsApp for Android prior to v2.20.35 and WhatsApp Business for Android prior to v2.20.20 are affected by CVE-2020-1894.
How can the CVE-2020-1894 vulnerability be exploited?
The CVE-2020-1894 vulnerability can be exploited by playing a specially crafted push to talk message on WhatsApp for Android and WhatsApp Business for Android.
Is there a fix available for CVE-2020-1894?
Yes, users should update to WhatsApp for Android version 2.20.35 and WhatsApp Business for Android version 2.20.20 to fix the CVE-2020-1894 vulnerability.