Exposure of Resource to Wrong Sphere in WhatsApp Messenger for Android and WhatsApp Business for Android - CVE-2021-24027
Published: April 16, 2021 / Updated: April 18, 2021
Vulnerability identifier: #VU52295
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-24027
CWE-ID:
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a malicious application to gain access to sensitive information on the system.
The vulnerability exists due to a cache configuration issue. A malicious application installed on the device with access to external storage can read cached TLS data.
Affected software
WhatsApp Messenger for Android
WhatsApp Business for Android
WhatsApp Business for Android
How to mitigate CVE-2021-24027
Install updates from vendor's website.
WhatsApp Messenger for Android - update to 2.21.4.18
WhatsApp Business for Android - update to 2.21.4.18
WhatsApp Business for Android - update to 2.21.4.18