CVE-2018-6350

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
14/06/2019
Last modified:
03/09/2025

Description

An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:* 2.18.99 (excluding)
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* 2.18.100.6 (excluding)
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows_phone:*:* 2.18.224 (excluding)
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* 2.18.100.2 (excluding)
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:* 2.18.276 (excluding)