CVE-2019-11932Active Exploitation(android-gif-drawable_project / android-gif-drawable)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch android-gif-drawable_project android-gif-drawable systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android-gif-drawable
  • whatsapp

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • False Positive: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-02-25); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
android-gif-drawablewhatsapp

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-25: 4Mentions · 2026-07-09: 1Mentions · 2026-09-26: 1Active Exploitation · 2026-02-25: 3Patch / Workaround · 2026-02-25: 3Technical Details · 2026-02-25: 302-2507-0909-26
Signal classification3 categories
Active Exploitation
350.0%
General
233.3%
False Positive
116.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-254
Active Exploitation3False Positive1
2026-07-091
General1
2026-09-261
General1
Full discourse6 posts
  • yousukezan@yousukezan
    General

    アプリ層から低レイヤーを打ち抜く:WhatsApp GIF脆弱性(CVE-2019-11932)をGemini×Claudeで徹底検証|Inlet_back https://zenn.dev/inlet_back/articles/2069cb693dd737 #zenn

    Post summary

    The post announces an in‑depth verification of WhatsApp GIF vulnerability CVE-2019-11932 using Gemini×Claude, but it does not provide evidence of exploitation, patches, or a PoC.

    000241.2K
    14.9K followersView on X
  • Grok@grok
    Active Exploitation

    Oui, cette information est véridique. La CVE-2025-21042 (Samsung, libimagecodec) permet à une image DNG malformée via WhatsApp d'exécuter du code distant et de prendre le contrôle, surtout avec téléchargement auto (exploité dans le spyware LANDFALL, patchée avril 2025). La CVE-2019-11932 sur GIF était similaire. Désactivez l'auto-download des médias et mettez à jour votre appareil pour vous protéger.

    Post summary

    CVE‑2025‑21042 is actively exploited through malformed DNG images sent via WhatsApp, with the spyware LANDFALL as a known example; a patch was released in April 2025 and users are advised to disable auto‑download and update their devices.

    10021371
    8.2M followersView on X
  • ambivalentcase🌈@ambivalentcase
    General

    @dinodaizovi @HacktronAI If you are in for mem corruption instead impact than CVE-2019-11932 on Jeff Bezos. A lot of 0day brokers do far crazier things nowadays.

    Post summary

    The tweet references CVE-2019-11932 in a vague comparison regarding vulnerability impact and 0day broker activity without detailing exploitation, patches, or PoCs.

    10001126
    321 followersView on X
  • Grok@grok
    Active Exploitation

    Oui, je confirme. Le mécanisme est exact : des images malformées (ex. DNG via CVE-2025-21042 sur Samsung, ou GIF via CVE-2019-11932) exploitent des failles dans les codecs de WhatsApp/Android pour un RCE zero-click, grâce au téléchargement auto. C'est réel, documenté (Unit 42, CISA), mais rare et ciblé sur des profils hautement prioritaires. Mets à jour ton OS et WhatsApp, et désactive le téléchargement auto si possible.

    Post summary

    The post confirms that malformed DNG and GIF images exploiting CVE-2025-21042 and CVE-2019-11932 are being used for zero‑click RCE attacks on WhatsApp/Android, with documentation from Unit 42 and CISA, and advises updating the OS/WhatsApp and disabling auto‑download.

    00000107
    8.2M followersView on X
  • Grok@grok
    Active Exploitation

    Oui, c’est vrai. Des vulnérabilités réelles comme CVE-2025-21042 (Samsung, images DNG via WhatsApp) ont permis des attaques zero-click exploitant le traitement automatique des images, menant à du code arbitraire. L’exemple historique CVE-2019-11932 (GIF sur Android/WhatsApp) le confirme aussi. Ces attaques sont rares, sophistiquées et visent surtout des cibles de valeur. Désactivez bien le téléchargement auto des médias, c’est la meilleure protection !

    Post summary

    The post confirms real zero‑click exploits of CVE‑2025‑21042 and CVE‑2019‑11932 on WhatsApp, noting that attacks have occurred and recommending disabling auto‑download as a mitigation.

    0000099
    8.2M followersView on X
  • M.Jed@DrcKinshasa
    False Positive

    @Katsuva_R ❌ Non, une “photo WhatsApp qui pirate ton téléphone” n’est pas un scénario normal. Un JPEG = données passives, pas du code → pas d’exécution = pas de hack. Oui, des cas rares ont existé (ex: CVE-2019-11932), mais ça exige zero-day + exploit avancé. Le vrai risque: phishing. https://t.co/ML3JA7Ucrm

    Post summary

    The tweet debunks the misconception that a WhatsApp photo can hack a phone, clarifying that JPEGs are passive data and that CVE‑2019‑11932 would require a zero‑day and advanced exploit to be used maliciously.

    00000458
    379 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appandroid-gif-drawable_projectandroid-gif-drawable---
Appwhatsappwhatsapp-android-

Explore more