CVE-2020-1909

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
03/11/2020
Last modified:
06/11/2020

Description

A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* 2.20.111 (excluding)
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* 2.20.111 (excluding)


References to Advisories, Solutions, and Tools