Whisperfish develops utility libraries and components for mobile messaging and data processing, with observed vulnerability exposure centered on input validation and error handling in the blurhash image-hashing library and phone-number parsing modules. The recurring weakness classes—improper validation of input quantities, missing error reporting, and uncaught exceptions—reflect common pitfalls in parsing and format-handling code where boundary conditions and exceptional states require explicit defensive coverage. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whisperfish over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42444HIGH phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may p | Sep 19, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-42447HIGH blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. | Sep 19, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whisperfish.
Media articles that mention a CVE ID that affects a product developed by Whisperfish — matched by CVE ID, not by vendor name.