CVE-2022-36934
Published on: Not Yet Published
Last Modified on: 09/24/2022 02:31:00 AM UTC
Certain versions of Whatsapp from Whatsapp contain the following vulnerability:
An integer overflow in WhatsApp could result in remote code execution in an established video call.
- CVE-2022-36934 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Meta - WhatsApp for iOS version < 2.22.16.12
- Affected Vendor/Software:
Meta - WhatsApp Business for iOS version < 2.22.16.12
- Affected Vendor/Software:
Meta - WhatsApp for Android version < 2.22.16.12
- Affected Vendor/Software:
Meta - WhatsApp Business for Android version < 2.22.16.12
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
WhatsApp Security Advisories | www.whatsapp.com text/html |
![]() |
Related QID Numbers
- 630827 Whatsapp for Android and iOS Multiple Vulnerabilities
Exploit/POC from Github
tool for exploiting whatsapp rce
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | All | All | All | All | ||
Application | All | All | All | All | ||
Application | All | All | All | All | ||
Application | All | All | All | All |
- cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:-:android:*:*:
- cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:-:iphone_os:*:*:
- cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:business:android:*:*:
- cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:business:iphone_os:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-36934 : An integer overflow in WhatsApp could result in remote code execution in an established video call… twitter.com/i/web/status/1… | 2022-09-22 21:37:23 |
![]() |
Potentially Critical CVE Detected! CVE-2022-36934 An integer overflow in WhatsApp could result in remote code execu… twitter.com/i/web/status/1… | 2022-09-22 22:55:55 |
![]() |
CVE-2022-36934 | 2022-09-22 22:38:54 |
![]() |
WhatsApp Remote Code Execution: CVE-2022-36934 CVE-2022-36934 | 2022-09-24 10:14:26 |
![]() |
CVE-2022-36934: WhatsApp execute arbitrary code flaw | 2022-09-26 05:57:34 |
![]() |
CVE-2022–36934: An integer overflow in WhatsApp leading to remote code execution in an established… | 2022-09-28 11:50:46 |