CVE-2019-11932 is a critical double free vulnerability in the DDGifSlurp function of the android-gif-drawable library, affecting WhatsApp for Android (versions prior to 2.19.244) and other Android applications utilizing this library. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through a specially crafted GIF image. Rated 8.8 HIGH on CVSS, it presents a significant risk with high impact on confidentiality, integrity, and availability, requiring user interaction (UI:R) for exploitation. While not listed in CISA KEV, public exploit code (EDB-47515) exists, and the vulnerability has garnered substantial community discussion and media coverage, indicating a high level of awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.19.244CPE matchmatch criteria | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:* | ||
< 1.2.18CPE matchmatch criteria | cpe:2.3:a:android-gif-drawable_project:android-gif-drawable:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.