CVE-2019-3568Active Exploitation(whatsapp / whatsapp)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch whatsapp whatsapp systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

4.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-10. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • whatsapp
  • whatsapp_business

Threat summary

  • Active exploitation appears in 5 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 5 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Peaked 5d ago at 2 mentions (2026-05-14); latest day: 2
  • 11 total mentions across 9 days

Affected systems

Vendors
Products
whatsappwhatsapp_business

Deep dive

Activity timeline11 mentions / 9d
01122Mentions · 2026-03-15: 1Mentions · 2026-03-28: 1Mentions · 2026-04-20: 1Mentions · 2026-05-14: 2Mentions · 2026-06-08: 1Mentions · 2026-06-11: 1Mentions · 2026-07-02: 1Mentions · 2026-08-10: 1Mentions · 2026-09-08: 2Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-07-02: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-03-15: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-08: 1Technical Details · 2026-07-02: 1Technical Details · 2026-09-08: 103-1503-2804-2005-1406-0806-1107-0208-1009-08
Signal classification3 categories
Active Exploitation
545.5%
General
436.4%
Patch
218.2%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-151
Patch1
2026-03-281
Active Exploitation1
2026-04-201
Patch1
2026-05-142
Active Exploitation1General1
2026-06-081
Active Exploitation1
2026-06-111
Active Exploitation1
2026-07-021
Active Exploitation1
2026-08-101
General1
2026-09-082
General2
Full discourse11 posts
  • Tal Be'ery@TalBeerySec
    General

    @Zimperium @_coreDump's analysis of the 2019 WhatsApp VoIP stack vuln (CVE-2019-3568) https://zimperium.com/blog/whatsapp-buffer-overflow-vulnerability-under-the-scope https://t.co/lLr8STTohi

    Post summary

    The tweet links to a blog post that analyzes the CVE-2019-3568 WhatsApp buffer overflow, but provides no PoC, exploit code, active usage, patch, or false‑positive claim.

    01017151.3K
    11.2K followersView on X
  • chalequeadorcito@chalekeadorcito
    General

    @cobaltcstar1 @JuanKassabjiT eso se llama trasmision de payload ofuscado, investiga por ejemplo la vulnerabilidad VoIP - WhatsApp CVE-2019-3568 ese ataque consiste en esconder el hack en los procesos automáticos de interpretación del dispositivo (sin clicks) como llamadas, encabezados, operaciones en fonts..

    Post summary

    The message references CVE-2019-3568 but does not provide any PoC, exploit, active usage, patch, or detailed technical information.

    20012250
    227 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    في مايو 2019، اكتشفت (WhatsApp) ثغرة خطيرة في ميزة الاتصال الصوتي (CVE-2019-3568). الثغرة كانت تسمح لـ (NSO) انهم يخترقون الجوال بمجرد الاتصال عبر مكالمة واتساب، وحتى لو لم يرد الضحية على المكالمة، يتم تثبيت (Pegasus) في الخلفية، ويمسح سجل المكالمة لكي لا يترك أثراً.

    Post summary

    The text reports live exploitation of CVE‑2019‑3568 by NSO, enabling Pegasus installation during a WhatsApp voice call, with no PoC, exploit code, or patch mentioned.

    10012522
    49.3K followersView on X
  • Sebastián Ricaurte@serial918
    Active Exploitation

    @hyperconectado FBI, CISA, papers académicos y hasta WhatsApp en 2019 documentaron ataques donde llamadas se usaron para robar credenciales o comprometer dispositivos. El exploit CVE-2019-3568 permitía infectar vía llamada VoIP incluso sin contestar. No desinformes.

    Post summary

    CISA and FBI documented real‑world exploitation of CVE‑2019‑3568, enabling device infection through VoIP calls without user consent.

    10030217
    82 followersView on X
  • M@MOH_580
    General

    @A9_4 مالك لوا يا عبدالرحمن، احياناً فيه ثغرات في النظام/البرنامج وتستغل حتى بدون ما ترد على المكالمة ونعرف انها نادرة جداً ولكنها مب مستحيلة واقرب مثال CVE-2019-3568

    Post summary

    The tweet simply cites CVE‑2019‑3568 as a known but rarely used vulnerability without providing any technical, exploit, or mitigation information.

    100201.1K
    35 followersView on X
  • Sebastián Ricaurte@serial918
    General

    @hyperconectado Otra cosa distinta es afirmar que “cualquier llamada spam te hackea automáticamente”. Eso sí es raro, pero pasa; https://nvd.nist.gov/vuln/detail/CVE-2019-3568

    Post summary

    The tweet simply mentions CVE-2019-3568 and notes that spam calls may exploit it, but offers no technical details, proof of concept, or evidence of active exploitation.

    1002055
    82 followersView on X
  • Grok@grok
    Active Exploitation

    Specific exploit messages aren't publicly detailed (to prevent aiding attackers), as they're zero-click zero-days processed invisibly. Known examples: - WhatsApp 2019: Malicious VoIP call (even missed; CVE-2019-3568) on 1,400+ targets. - iMessage 2021: FORCEDENTRY—crafted message received via iMessage (no open/click needed). - Similar 2025 WhatsApp zero-click (CVE-2025-55177) chained with iOS flaw. Reports from Citizen Lab, Google Project Zero, Amnesty. Keep OS/messaging apps updated.

    Post summary

    The excerpt confirms that CVE-2019-3568 and CVE-2025-55177 were actively exploited in zero‑click attacks affecting many users, with no PoC disclosed, and stresses keeping messaging apps updated as a mitigation.

    10020192
    8.5M followersView on X
  • 22@CHM_52
    Active Exploitation

    انتم تعرفون ان هالاتصالات ذي مو عشوائية ؟! وانها ثغره قديمه بالواتس اسمها " CVE-2019-3568 " وهم يتصلون عليكم عشان يخترقون اجهزتكم حتى لو ما رديتوا عليهم https://t.co/JH48FkIBkI

    Post summary

    The post warns that attackers are exploiting the old WhatsApp vulnerability CVE-2019-3568 by contacting users, attempting to hack devices if the users do not answer.

    00011485
    48 followersView on X
  • CiberBaur@BotBauR
    Patch

    5/6 **Defensa**: - Actualiza iOS/Android a versiones parcheadas (iOS 14.8+). - Usa Signal o WhatsApp con encriptación de extremo a extremo. - Monitorea llamadas no contestadas en WhatsApp (posible CVE-2019-3568). - Revisa logs de actualizaciones de apps críticas.

    Post summary

    The post emphasizes applying patched OS versions, using encrypted messaging, and monitoring potential CVE-2019-3568 activity, with a focus on patching as the primary defensive measure.

    1001082
    153 followersView on X
  • Inviolable | Smart Global Tech@inviolableio
    Active Exploitation

    In 2019, NSO Group exploited a buffer overflow in WhatsApp's VOIP stack. One missed call. No tap required. Documented as CVE-2019-3568. WhatsApp patched it. NSO moved to other delivery vectors.

    Post summary

    CVE-2019-3568, a buffer overflow in WhatsApp's VOIP stack, was actively exploited by NSO Group and subsequently patched by WhatsApp.

    1000044
    35 followersView on X
  • 🆃🅷🅴 🅳🅰🆁🅺 🅾🅽🅴 ️️ ️️ ️️ ️️ ️️ ️️ ️️ ️️ ️️@Angel__Q8
    Patch

    @YinniiY الثغرة اللي تكلم عنها قديمة وتصير عن طريق الاتصال لأنها تستهدف Voice over ip (VOIP) protocol رقمها CVE-2019-3568 تشتغل على اصدارات قديمة للواتساب 12.9 وأقل مكتشف الثغرة ماراح يستهدف ناس عاديين وتنباع بفلوس بمبالغ لحكومات ومؤسسات عسكرية ومنظمات ويتم غلقها بتحديثات قبل لا تنتشر

    Post summary

    The post describes CVE‑2019‑3568 as an old vulnerability targeting older WhatsApp VoIP, notes that it will be fixed via updates, and provides basic technical details but no exploit or active usage claims.

    10000160
    234 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appwhatsappwhatsapp-android-
Appwhatsappwhatsapp-iphone_os-
Appwhatsappwhatsapp-tizen-
Appwhatsappwhatsapp-windows_phone-
Appwhatsappwhatsapp_business-android-
Appwhatsappwhatsapp_business-iphone_os-

Explore more