A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write.
Conclusion & alert: CVE-2021-24026 is rated Moderate Risk (60.9/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.44%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-07-22 | 0.55% | 0.44% | -0.11% |
| 2 | 2025-03-30 | 1.14% | 0.55% | -0.59% |
| 3 | 2025-03-29 | — | 1.14% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| < 2.21.3 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:* | ||
| < 2.21.3 | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* | ||
| whatsapp_business | < 2.21.3 | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:* | |
| whatsapp_business | < 2.21.32 | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* |
| URL | Tags |
|---|---|
| https://www.whatsapp.com/security/advisories/2021/ | Vendor Advisory |