CVE-2019-3568
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedA buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceA buffer overflow vulnerability exists in WhatsApp's Voice over IP (VOIP) stack that allows remote code execution through specially crafted RTCP (Real-time Transport Control Protocol) packets sent to a target phone number. The overflow occurs due to insufficient bounds checking when processing RTCP packet data in the VOIP stack, enabling attackers to overwrite memory and execute arbitrary code. The vulnerability affects multiple WhatsApp clients across Android, iOS, Windows Phone, and Tizen platforms.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 2.18.15< 2.18.348< 2.19.51< 2.19.134< 2.19.44< 2.19.51CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Check WhatsApp versionOpen WhatsApp, go to Settings > Help > About to view the installed version numberAffected if The version is less than 2.18.15, OR between 2.18.15 and 2.18.347, OR between 2.18.348 and 2.19.50, OR between 2.19.51 and 2.19.133 (i.e., any version lower than 2.19.134)
-
Check WhatsApp Business versionOpen WhatsApp Business, go to Settings > Help > About to view the installed version numberAffected if The version is less than 2.19.44, OR between 2.19.44 and 2.19.50 (i.e., any version lower than 2.19.51)
-
Verify voice calling feature statusThe vulnerability affects RTCP packet handling in the voice calling feature. Confirm that voice calling is enabled in the app settings under Settings > Account > Privacy > Voice Calls (or similar depending on version). The app must have VOIP capability present to process the malformed RTCP packets.Affected if Voice calling feature is enabled and the app version falls within the affected ranges above
If either WhatsApp or WhatsApp Business is installed at a version below the patched releases (2.19.134 for WhatsApp, 2.19.51 for WhatsApp Business) and voice calling functionality is available, the device is vulnerable to remote code execution via specially crafted RTCP packets.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped2.18.152.18.3482.19.44
Users must update WhatsApp to the patched versions (v2.19.134+ for Android, v2.19.51+ for iOS, v2.19.44+ for WhatsApp Business Android, v2.18.348+ for Windows Phone, v2.18.15+ for Tizen) to remediate this vulnerability. Organizations should ensure all devices have the latest WhatsApp version installed.
WhatsApp Android v2.19.134, WhatsApp Business Android v2.19.44, WhatsApp iOS v2.19.51, WhatsApp Business iOS v2.19.51, WhatsApp Windows Phone v2.18.348, WhatsApp Tizen v2.18.15
- Identify the affected platform (Android, iOS, Windows Phone, or Tizen)
- Check the current installed version of WhatsApp or WhatsApp Business in the device settings
- For Android: Open Google Play Store, search for WhatsApp or WhatsApp Business, and update to version 2.19.134 (WhatsApp) or 2.19.44 (WhatsApp Business)
- For iOS: Open Apple App Store, search for WhatsApp or WhatsApp Business, and update to version 2.19.51
- For Windows Phone: Open Microsoft Store, search for WhatsApp, and update to version 2.18.348
- For Tizen: Open Tizen Store, search for WhatsApp, and update to version 2.18.15
- After updating, verify the new version is installed by checking the app version in settings
- Ensure auto-updates are enabled for future security patches
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation4.0 h
- Implementation8.0 h
- Testing4.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,120.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2019-3568 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2019-3568 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data