Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Whatsapp

First CVE: May 18, 2017Active for: 9 yearsTotal CVEs: 46
71.6
VTI Score
TOP TARGET

WhatsApp's vulnerability footprint spans a modest product portfolio—including the core messaging application, business and desktop variants, and enterprise client—that collectively achieve global reach as widely deployed communication infrastructure. Despite the relatively focused set of affected products, vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a moderate tendency toward confirmed in-the-wild exploitation and cataloging by CISA. The recurring weakness classes, dominated by memory-safety issues including out-of-bounds writes, heap-based and stack-based buffer overflows, and race conditions, reflect the performance and real-time demands of a large native codebase handling untrusted network input at scale. Defenders should treat WhatsApp advisories as high-priority given the severity profile and the application's ubiquity in personal, business, and organizational communications; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
6.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Whatsapp over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 18, 2017
9 years ago
Most Recent CVE
May 1, 2026
84 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-18426HIGH
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Ex
Jan 21, 20208.294YESYES
CVE-2019-3568CRITICAL
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects W
May 14, 20199.886YESNO
CVE-2025-55177MEDIUM
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78
Aug 29, 20255.466YESNO
CVE-2019-11932HIGH
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.
Oct 3, 20198.864NOYES
CVE-2025-30401MEDIUM
A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’
Apr 5, 20256.736NONO
CVE-2022-36934CRITICAL
An integer overflow in WhatsApp could result in remote code execution in an established video call.
Sep 22, 20229.832NONO
CVE-2020-1889CRITICAL
A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a rem
Sep 3, 202010.032NONO
CVE-2021-24042CRITICAL
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior
Jan 4, 20229.831NONO
CVE-2021-24041CRITICAL
A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a u
Dec 7, 20219.831NONO
CVE-2019-11933CRITICAL
A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code
Oct 23, 20199.831NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
35%
28%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (17.4%)
Network36 (78.3%)
Unknown0 (0.0%)
Physical2 (4.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (91.3%)
High4 (8.7%)
Unknown0 (0.0%)
User Interaction
None30 (65.2%)
Unknown0 (0.0%)
Required16 (34.8%)
Privileges Required
Low5 (10.9%)
High0 (0.0%)
None41 (89.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
3 CVEs
6.5% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Whatsapp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Whatsapp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Whatsapp's Products

View all 2 CNAs →

Top CWEs