SB2019051014 - Information disclosure in WhatsApp Messenger for Android



SB2019051014 - Information disclosure in WhatsApp Messenger for Android

Published: May 10, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019051014
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2019-3566)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38.


Remediation

Install update from vendor's website.