CVE-2020-1902: Infoleak
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-1902?
CVE-2020-1902 is a vulnerability found in WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49.
How does CVE-2020-1902 affect WhatsApp for Android?
CVE-2020-1902 allows a user running a quick search on a highly forwarded message to be sent to the Google service over plain HTTP, potentially compromising their privacy and security.
What is the severity of CVE-2020-1902?
The severity of CVE-2020-1902 is high, with a severity value of 7.5.
How can I check if my version of WhatsApp is affected by CVE-2020-1902?
If you are using WhatsApp for Android v2.20.108 to v2.20.140 or WhatsApp Business for Android v2.20.35 to v2.20.49, you may be affected by CVE-2020-1902.
How can I fix CVE-2020-1902?
To fix CVE-2020-1902, update your WhatsApp for Android to the latest version available (v2.20.141 or above) or update your WhatsApp Business for Android to v2.20.50 or above.