CVE-2020-1907: Critical severity whatsapp vulnerability
A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 could have allowed arbitrary code execution when parsing the contents of an RTP Extension header.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-1907?
CVE-2020-1907 refers to a stack overflow vulnerability in WhatsApp for Android, WhatsApp Business for Android, WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Portal.
What is the severity of CVE-2020-1907?
CVE-2020-1907 has a severity rating of 9.8 out of 10, which is classified as critical.
How does CVE-2020-1907 allow arbitrary code execution?
CVE-2020-1907 allows arbitrary code execution by exploiting a stack overflow vulnerability in the affected WhatsApp versions.
Which versions of WhatsApp are affected by CVE-2020-1907?
WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 are affected by CVE-2020-1907.
How can I fix CVE-2020-1907?
To fix CVE-2020-1907, update WhatsApp to version v2.20.196.16 or later for Android, v2.20.90 or later for iOS, v2.20.196.12 or later for WhatsApp Business for Android, v2.20.90 or later for WhatsApp Business for iOS, and v173.0.0.29.505 or later for WhatsApp for Portal.