LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-3568: WhatsApp VOIP Stack Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 19, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-3568 to its Known Exploited Vulnerabilities catalog on Apr 19, 2022, with a federal patch deadline of May 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

CVE-2019-3568 is a stack-based buffer overflow in the WhatsApp VOIP stack that can lead to remote code execution. An attacker can trigger it by sending a specially crafted series of RTCP packets toward a target phone number. For IT and security teams, this matters because successful exploitation can give an attacker code execution on the device running WhatsApp, with no need for the user to accept a call or open a message in the usual sense. Confirm exact affected builds and fixed versions against the vendor advisory.

How it works

The weakness is classified as CWE-122 (heap-based or stack-based buffer overflow in the VOIP path; the advisory frames it as a VOIP stack buffer overflow). In plain terms, the VOIP handling code does not properly bound the data it copies or processes when it receives certain RTCP packets. An attacker who can reach the target’s WhatsApp VOIP endpoint with a crafted sequence of those packets can overflow a buffer and potentially seize control of execution flow.

Abuse does not require inventing exotic local exploits: the public description is that remote code execution is possible via RTCP packets aimed at a phone number associated with WhatsApp. Specifics of packet layout, exact memory corruption path, or reliability must be taken only from the vendor advisory and reputable technical write-ups that cite it—do not assume unstated exploit mechanics.

Am I affected? How to find it in your systems

WhatsApp runs primarily on mobile endpoints (Android and iOS handsets and, where deployed, WhatsApp desktop or business clients that share the same VOIP stack). In enterprise settings it appears on BYOD and corporate-owned phones, sometimes on shared or kiosk devices, and in any environment where staff use WhatsApp for voice or video.

How to remediate

Patch first. Apply the updates Meta Platforms issued for WhatsApp as described in the vendor advisory and follow CISA’s required action: apply updates per vendor instructions. Push the fixed client versions through MDM, app stores, or enterprise distribution channels and verify installation.

If you can't patch immediately

Reduce exposure until the fixed WhatsApp builds are installed everywhere.

If your data may have been exposed

Actively exploited remote-code-execution flaws in messaging clients can lead to device compromise and subsequent data theft; ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected devices, preserve logs and crash evidence, rotate credentials accessible from those devices, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMeta Platforms · WhatsApp
WeaknessCWE-122
Added to CISA KEVApr 19, 2022
Federal patch deadlineMay 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities