Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2020-1903

MEDIUM 5.5

An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts.

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS 0.66% exploit very unlikely percentile 48.2%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
whatsapp whatsapp
iOS
<2.20.61
whatsapp whatsapp_business
iOS
<2.20.61
View on NVD ↗ Advisory · www.whatsapp.com