WhatsApp's vulnerability footprint spans a modest product portfolio—including the core messaging application, business and desktop variants, and enterprise client—that collectively achieve global reach as widely deployed communication infrastructure. Despite the relatively focused set of affected products, vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward confirmed in-the-wild exploitation and cataloging by CISA. The recurring weakness classes, dominated by memory-safety issues including out-of-bounds writes, heap-based and stack-based buffer overflows, and race conditions, reflect the performance and real-time demands of a large native codebase handling untrusted network input at scale. Defenders should treat WhatsApp advisories as high-priority given the severity profile and the application's ubiquity in personal, business, and organizational communications; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whatsapp over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18426HIGH A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Ex | Jan 21, 2020 | 8.2 | 94 | YES | YES |
CVE-2019-3568CRITICAL A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects W | May 14, 2019 | 9.8 | 86 | YES | NO |
CVE-2025-55177MEDIUM Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 | Aug 29, 2025 | 5.4 | 66 | YES | NO |
CVE-2019-11932HIGH A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19. | Oct 3, 2019 | 8.8 | 64 | NO | YES |
CVE-2025-30401MEDIUM A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’ | Apr 5, 2025 | 6.7 | 36 | NO | NO |
CVE-2022-36934CRITICAL An integer overflow in WhatsApp could result in remote code execution in an established video call. | Sep 22, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-1889CRITICAL A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a rem | Sep 3, 2020 | 10.0 | 32 | NO | NO |
CVE-2021-24042CRITICAL The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior | Jan 4, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-24041CRITICAL A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a u | Dec 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-11933CRITICAL A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code | Oct 23, 2019 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whatsapp.
Media articles that mention a CVE ID that affects a product developed by Whatsapp — matched by CVE ID, not by vendor name.