CVE-2021-24026
Published Apr 6, 2021
Last updated 4 years ago
Overview
- Description
- A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write.
- Source
- cve-assign@fb.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "A2F90DE0-CAA1-417A-9D8A-279C966CF126", "versionEndExcluding": "2.21.3" }, { "criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*", "vulnerable": true, "matchCriteriaId": "63C685C5-9E36-456E-8627-F7789BF9A817", "versionEndExcluding": "2.21.3" }, { "criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "8C00EB21-B107-4D99-9D1E-09B0FA443F3F", "versionEndExcluding": "2.21.3" }, { "criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*", "vulnerable": true, "matchCriteriaId": "735449C3-06DF-4F11-B821-5DDB5F2BC2F1", "versionEndExcluding": "2.21.32" } ], "operator": "OR" } ] } ]