Blog

Another WhatsApp Vulnerability Has Been Found

By baypointetech • November 21, 2019

WhatsApp is the most popular messaging platform in the world.


Unfortunately, that means it's got a giant bullseye on it where hackers are concerned.


In recent months, the company has faced no end of troubles as a raft of vulnerabilities have been exposed and exploited by hackers from every corner of the globe.


The company is still reeling from the blowback associated with these various issues, but their troubles don't seem to be over yet. Just last month, WhatsApp quietly found and patched another vulnerability. This one is tracked as CVE-2019-11931. It is a stack-based buffer overflow issue relating to the way that older WhatsApp versions parsed MP4 metadata, allowing attackers to launch denial-of-service or remote code execution attacks.


All a hacker needed in order to exploit the flaw was a target's phone number and a specially crafted MP4 file. It just had to be constructed in such a way that it installed a backdoor upon opening. From there, a wide range of malware could be installed at the hackers' leisure. Worse, this vulnerability was found in both the consumer and Enterprise versions of WhatsApp for all major platforms, including Windows, iOS, and Android.


An advisory bulletin was recently published by WhatsApp's parent company, Facebook. See the list of versions they provided below.


The list of affected versions are as follows:


  • Business for iOS versions prior to 2.19.100
  • Business for Android versions prior to 2.19.104
  • Windows Phone versions prior to and including 3.18.368
  • Enterprise Client versions prior to 2.25.3
  • iOS versions prior to 2.19.100
  • Android versions prior to 2.19.274


If there's a silver lining here, it is that the company has confirmed that there have been no instances of this exploit having been used 'in the wild' and the company has already issued a patch. If you're one of WhatsApp's legions of users, check to be sure you're running the latest version. If not, update immediately to be on the safe side.


Used with permission from Article Aggregator

Related Posts

By BayPointe Technology • September 30, 2026
Find out whether your business backups can support recovery. Plan restore tests, measure results, and address gaps before an outage disrupts work.
By BayPointe Technology • September 23, 2026
Help employees recognize phishing emails, verify unusual requests, and report concerns with a practical process for Northeast Ohio businesses.
Stressed man at desk with hand on face, holding glasses near a computer and moving boxes
By BayPointe Technology • September 16, 2026
Recurring IT issues, growing support demands, or unclear security responsibilities? Learn when your Northeast Ohio business should consider managed IT services.
Blue illuminated curved metal structure with repeating ribbed arches
By BayPointe Technology • September 9, 2026
Plan office-move IT tasks, including internet installation, cabling, phones, equipment, vendor coordination, and opening-day readiness checks.
Two coworkers reviewing data on dual monitors in a bright office, one pointing at the screen
By BayPointe Technology • September 2, 2026
Organize business file sharing with clear owners, appropriate permissions, external access reviews, and practical rules employees can follow.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256