CVE-2020-1909
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
03/11/2020
Last modified:
06/11/2020
Description
A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* | 2.20.111 (excluding) | |
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* | 2.20.111 (excluding) |
To consult the complete list of CPE names with products and versions, see this page