QID 630801

Date Published: 2022-04-19

QID 630801: WhatsApp For ios Out-of-bounds Read Vulnerability

A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet during an established call.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to CVE-2021-24043 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630801

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-24043 iOS URL Logo nvd.nist.gov/vuln/detail/CVE-2021-24043