CVE-2023-38537: Use After Free
A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38537.
What is the severity of CVE-2023-38537?
The severity of CVE-2023-38537 is medium with a CVSS score of 5.6.
What is the description of CVE-2023-38537?
CVE-2023-38537 is a race condition in a network transport subsystem that led to a heap use-after-free issue in established or unsilenced incoming audio/video calls, potentially resulting in app termination or unexpected control flow.
Which software is affected by CVE-2023-38537?
The affected software is Whatsapp version up to and excluding 2.2338.12 for desktop on Mac OS X.
How can I fix CVE-2023-38537?
To fix CVE-2023-38537, it is recommended to update Whatsapp to the latest version available.