First published: Tue Oct 06 2020(Updated: )
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Whatsapp Whatsapp | >=2.20.108<=2.20.140 | |
Whatsapp Whatsapp Business | >=2.20.35<=2.20.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1902 is a vulnerability found in WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49.
CVE-2020-1902 allows a user running a quick search on a highly forwarded message to be sent to the Google service over plain HTTP, potentially compromising their privacy and security.
The severity of CVE-2020-1902 is high, with a severity value of 7.5.
If you are using WhatsApp for Android v2.20.108 to v2.20.140 or WhatsApp Business for Android v2.20.35 to v2.20.49, you may be affected by CVE-2020-1902.
To fix CVE-2020-1902, update your WhatsApp for Android to the latest version available (v2.20.141 or above) or update your WhatsApp Business for Android to v2.20.50 or above.