CVE-2020-1906: WhatsApp

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with E-AC-3 audio streams.

Affected products

  • WhatsApp WhatsApp: before 2.20.130 (fixed in 2.20.130)
  • WhatsApp WhatsApp Business: before 2.20.46 (fixed in 2.20.46)

Published 2020-10-06. Last modified 2026-06-17.