QID 630680
Date Published: 2021-05-10
QID 630680: WhatsApp For Android Exposure of Resource to Wrong Sphere Vulnerability
A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the devices external storage to read cached TLS material.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-24027 to address this issue and obtain more information.
Vendor References
- CVE-2021-24027 -
nvd.nist.gov/vuln/detail/CVE-2021-24027
CVEs related to QID 630680
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-24027 | Android |
|