CVE-2020-1910: WhatsApp

High severity, CVSS 7.8. EPSS: 5.1% chance of exploitation in the next 30 days.

A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image.

Affected products

  • WhatsApp WhatsApp: before 2.21.1.13 (fixed in 2.21.1.13)
  • WhatsApp WhatsApp Business: before 2.21.1.13 (fixed in 2.21.1.13)

Published 2021-02-02. Last modified 2026-06-17.