A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
Conclusion & alert: CVE-2019-3568 is rated Critical Active Threat (93.6/100): CVSS Critical severity, with high exploitation likelihood (EPSS 39.17%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-04-19) affecting Meta Platforms / WhatsApp. a weakness (CWE-122) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: WhatsApp VOIP Stack Buffer Overflow Vulnerability · CISA KEV detail
: 2022-04-19
: 2022-05-10
: Apply updates per vendor instructions.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 47.37% | 39.17% | -8.20% |
| 2 | 2026-06-06 | 47.96% | 47.37% | -0.59% |
| 3 | 2026-05-22 | — | 47.96% | — |
Full EPSS history (72 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| < 2.18.15 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:tizen:*:* | ||
| < 2.18.348 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows_phone:*:* | ||
| < 2.19.51 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* | ||
| < 2.19.134 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:* | ||
| whatsapp_business | < 2.19.44 | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:* | |
| whatsapp_business | < 2.19.51 | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/108329 | Broken Link Third Party Advisory VDB Entry |
| https://www.facebook.com/security/advisories/cve-2019-3568 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-3568 | US Government Resource |