Vulnerability Intelligence Report
CVE-2018-6350
An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:1.69%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-125 ↗Out-of-bounds Read (CWE-125)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| WhatsApp for Android | 2.18.276 (affected), unspecified < 2.18.276 (affected) | |
| WhatsApp Business for Android | 2.18.99 (affected), unspecified < 2.18.99 (affected) | |
| WhatsApp for iOS | 2.18.100.6 (affected), unspecified < 2.18.100.6 (affected) | |
| WhatsApp Business for iOS | 2.18.100.2 (affected), unspecified < 2.18.100.2 (affected) | |
| WhatsApp for Windows Phone | 2.18.224 (affected), unspecified < 2.18.224 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.693%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | |
| Reserved | 2018-01-26T00:00:00 |
| Published | 2019-06-14T17:02:57 |
| Last Updated | 2024-08-05T06:01:48 |
Community Chatter & Buzz