CVE-2021-24041 is a critical out-of-bounds write vulnerability affecting WhatsApp and WhatsApp Business for Android versions prior to 2.21.22.7. This flaw, stemming from a missing bounds check in image blurring code, could be triggered by sending a specially crafted malicious image. With a CVSS score of 9.8 (Critical), it presents a severe risk, allowing for potential complete compromise of confidentiality, integrity, and availability without user interaction. While the vulnerability has a high FAUCET Risk Score of 79/100 and some community discussion, there is currently no evidence of active exploitation, nor are public exploit codes like Metasploit or ExploitDB available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.21.22.7CPE matchmatch criteria | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:* | ||
< 2.21.22.7CPE matchmatch criteria | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.