cbcvebase.
CVE-2020-1909
published 2020-11-03

CVE-2020-1909: A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory…

PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.25%
81.0th percentile
A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold.

Affected

8 ranges
VendorProductVersion rangeFixed in
facebookwhatsapp_business_for_ios
facebookwhatsapp_business_for_ios>= 2.20.81 < unspecifiedunspecified
facebookwhatsapp_business_for_ios>= unspecified < 2.20.1112.20.111
facebookwhatsapp_for_ios
facebookwhatsapp_for_ios>= 2.20.81 < unspecifiedunspecified
facebookwhatsapp_for_ios>= unspecified < 2.20.1112.20.111
whatsappwhatsapp< 2.20.1112.20.111
whatsappwhatsapp_business< 2.20.1112.20.111

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.