CERT-In Vulnerability Note
CIVN-2021-0077
Multiple Vulnerabilities in WhatsApp
Original Issue Date:April 12, 2021
Severity Rating: HIGH
Software Affected
- WhatsApp and WhatsApp Business for Android prior to v2.21.4.18
- WhatsApp and WhatsApp Business for iOS prior to v2.21.32
Overview
Multiple vulnerabilities have been reported in WhatsApp applications which could allow a remote attacker to execute arbitrary code or access sensitive information on a targeted system.
Description
These vulnerabilities exist in WhatsApp applications due to a cache configuration issue and missing bounds check within the audio decoding pipeline.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code or access sensitive information on a targeted system.
Solution
- Update to the latest version from Google Play store or iOS App Store.
Vendor Information
WhatsApp
https://www.whatsapp.com/security/advisories/2021/
References
WhatsApp
https://www.whatsapp.com/security/advisories/2021/
CVE Name
CVE-2021-24027
CVE-2021-24026
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|