CVE-2020-1906: Buffer Overflow
A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with E-AC-3 audio streams.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-1906.
What is the severity of CVE-2020-1906?
The severity of CVE-2020-1906 is high with a severity value of 7.8.
Which software versions are affected by CVE-2020-1906?
WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 are affected by CVE-2020-1906.
How can an attacker exploit CVE-2020-1906?
An attacker can exploit CVE-2020-1906 by sending malformed local videos with E-AC-3 audio streams, triggering a buffer overflow and allowing an out-of-bounds write.
Is there a fix available for CVE-2020-1906?
To fix CVE-2020-1906, upgrade to WhatsApp for Android v2.20.130 or later, and WhatsApp Business for Android v2.20.46 or later.