CVE Vulnerabilities

CVE-2019-3566

Published: May 10, 2019 | Modified: Sep 14, 2021
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A bug in WhatsApp for Androids messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp users account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38.

Affected Software

Name Vendor Start Version End Version
Whatsapp Whatsapp 2.19.54 (including) 2.19.103 (including)
Whatsapp Whatsapp 2.19.52 (including) 2.19.52 (including)
Whatsapp_business Whatsapp 2.19.22 (including) 2.19.38 (including)

References