CVE-2019-11927: WhatsApp

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on the heap via specially-crafted EXIF tags in WEBP images. This issue affects WhatsApp for Android before version 2.19.143 and WhatsApp for iOS before version 2.19.100.

Affected products

  • WhatsApp WhatsApp: before 2.9.143 (fixed in 2.9.143); before 2.19.100 (fixed in 2.19.100)

Published 2019-09-27. Last modified 2026-06-17.