logo

WhatsApp Buffer Overflow Vulnerability: Under the Scope

ID: db821197-00b1-5728-9523-011415f8c178

STIX ID: report--db821197-00b1-5728-9523-011415f8c178

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2019-06-14

Date Updated: 2026-05-01

...
...

This zLabs blog analyzes CVE-2019-3568, a WhatsApp remote code execution vulnerability affecting iOS (and Android) clients: it identifies patched memory-corruption code paths (integer underflow and unchecked memcpy leading to buffer overflows), validates invocation during voice calls via debugger breakpoints, and demonstrates a PoC that an RCE could silently authorize a persistent WhatsApp Web session to hijack an account. The report discusses attacker goals, persistence and stealth trade-offs, and notes that Facebook patched the issue after reports of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.