Skip to content
appaloosa scout logo main rounded
MEDIUM 4.6

CVE-2020-1908

Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.

CVSS v3 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
whatsapp whatsapp iOS <2.20.100 cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
whatsapp whatsapp_business iOS <2.20.100 cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*
View on NVD ↗