First published: Tue Oct 06 2020(Updated: )
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Whatsapp Whatsapp | <2.20.185 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-1905.
The severity of CVE-2020-1905 is medium (3.3).
WhatsApp for Android versions up to 2.20.185 are affected by this vulnerability.
By sequentially guessing the URIs for previously opened attachments, a malicious third-party app could exploit this vulnerability in WhatsApp for Android.
To fix this vulnerability, update WhatsApp for Android to version 2.20.185 or higher.