- Known vulnerabilities
- 21
- Still open
- 0
- KEV open
- 0
- Max CVSS score
- 9.8
2 total (history)
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Known vulnerabilities (CVE)
Test a different version
| CVE |
|---|
|
CVE-2026-23866
Fixed
MEDIUM 4.3
Network Fixed in: > 2.26.15.72
|
|
CVE-2025-55179
Fixed
MEDIUM 5.4
Network Fixed in: 2.25.23.73
|
|
CVE-2025-55177
Fixed
MEDIUM 5.4
KEV
Network Fixed in: 2.25.21.73
|
|
CVE-2022-27492
Fixed
HIGH 7.8
Local Fixed in: 2.22.15.9
|
|
CVE-2022-36934
Fixed
CRITICAL 9.8
Network Fixed in: 2.22.16.12
|
|
CVE-2020-20096
Fixed
MEDIUM 6.5
Network Fixed in: > 2.19.80
|
|
CVE-2021-24042
Fixed
CRITICAL 9.8
Network Fixed in: 2.21.230
|
|
CVE-2021-24026
Fixed
CRITICAL 9.8
Network Fixed in: 2.21.3
|
|
CVE-2020-1909
Fixed
CRITICAL 9.8
Network Fixed in: 2.20.111
|
|
CVE-2020-1908
Fixed
MEDIUM 4.6
Physical Fixed in: 2.20.100
|
|
CVE-2020-1907
Fixed
CRITICAL 9.8
Network Fixed in: 2.20.90
|
|
CVE-2020-1904
Fixed
MEDIUM 5.5
Local Fixed in: 2.20.61
|
|
CVE-2020-1903
Fixed
MEDIUM 5.5
Local Fixed in: 2.20.61
|
|
CVE-2020-1901
Fixed
MEDIUM 5.3
Network Fixed in: 2.20.91.4
|
|
CVE-2020-1894
Fixed
HIGH 8.8
Network Fixed in: 2.20.30
|
|
CVE-2020-1891
Fixed
CRITICAL 9.8
Network Fixed in: 2.20.20
|
|
CVE-2019-18426
Fixed
HIGH 8.2
KEV
Network Fixed in: 2.20.10
|
|
CVE-2019-11931
Fixed
HIGH 7.8
Local Fixed in: 2.19.100
|
|
CVE-2019-11927
Fixed
HIGH 7.8
Local Fixed in: 2.19.100
|
|
CVE-2018-20655
Fixed
CRITICAL 9.8
Network Fixed in: 2.18.90.24
|
1 indeterminable CVE(s) hidden (missing current version or incompatible version schemes). · Show
Detailed scoring Security Score 100 Privacy Score 92
Security Score
Excellent
Composite: 50% open CVEs + 40% open KEVs + 10% vendor velocity.
-
Open CVEs 0/-50
0 CVEs
-
Open KEVs 0/-40
0 KEVs
-
Vendor 0/-10
100% fresh
Privacy Score
Respectful
Composite: 40% critical shared + 30% high shared + 20% high collected + 10% sensitive density.
-
Critical shared 0/-40
0 critical shared
-
High shared 0/-30
0 high + 0 medium shared
-
High collected -8/-20
2 high + 3 medium collected
2 high : Contacts, Location
3 moderate : Usage Data, User Content, Contact Info
-
Sensitive density 0/-10
40% sensitive
Context
Context
Description
WhatsApp from Meta est une application gratuite permettant d’envoyer des messages et de passer des appels, utilisée par plus de 2 milliards de personnes dans plus de 180 pays. Simple, fiable et privée, il s’agit de l’application idéale pour rester en contact avec vos proches partout dans le monde. WhatsApp fonctionne sur mobile, tablette et ordinateur, même avec des connexions lentes, et sans frais d’inscription*. Des messages et des appels privés dans le monde entier La protection de votre vie privée est notre priorité. Grâce au chiffrement de bout en bout, vous avez la certitude que vos messages et vos appels personnels restent entre vous et leurs destinataires. Personne, pas même WhatsApp, ne peut les lire ou les écouter. Des connexions simples et sécurisées, directement Tout ce dont vous avez besoin, c’est d’un numéro de téléphone. Aucun nom d’utilisateur ou identifiant n’est nécessaire. Vous pouvez rapidement voir qui parmi vos contacts utilise WhatsApp et commencer à discuter. Plus encore, vous pouvez facilement associer vos autres appareils, y compris les iPad, pour une communication plus fluide. Des appels vocaux et vidéo de qualité Vous pouvez passer gratuitement* d…
Data collected and shared
Source: App Store · App Privacy · 10 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
Other apps by this publisher
Apps published by WhatsApp Inc.
FAQ
FAQ: WhatsApp
Does WhatsApp have known security vulnerabilities?
WhatsApp (ios:net.whatsapp.WhatsApp) on iOS has 21 CVE referenced in NVD, 0 still open on the current version and 0 listed in the CISA KEV catalog. Absence of a CVE is not a security guarantee.
Is the current version of WhatsApp affected by any open CVE?
Version 26.22.76 of WhatsApp on iOS has no open CVE referenced in NVD. Absence of a CVE is not a security guarantee.
Is WhatsApp affected by an actively exploited vulnerability (CISA KEV)?
No CVE affecting WhatsApp (ios:net.whatsapp.WhatsApp) is currently in the CISA KEV catalog.
What is the latest known version of WhatsApp?
The most recent version of WhatsApp (ios:net.whatsapp.WhatsApp) tracked by Appaloosa Scout is 26.22.76, published by WhatsApp Inc..