"Two Remote Code Execution Vulnerabilities Patched in WhatsApp"

WhatsApp has recently patched two serious vulnerabilities that could be exploited for remote code execution.  One of the flaws, tracked as CVE-2022-36934 and rated "critical," is an integer overflow issue that affects WhatsApp for Android prior to 2.22.16.12, Business for Android prior to 2.22.16.12, iOS prior to 2.22.16.12, and Business for iOS prior to 2.22.16.12.  WhatsApp noted that an attacker can exploit the vulnerability for remote code execution during a video call.  The second issue, a high-severity flaw tracked as CVE-2022-27492, is an integer underflow that can be exploited for remote code execution by sending a specially crafted video file to the targeted user.  It has been patched in WhatsApp for Android and iOS with the release of versions 2.22.16.2 and 2.22.15.9, respectively.  According to security researchers at Malwarebytes, CVE-2022-36934 impacts the Video Call Handler component, while CVE-2022-27492 affects the Video File Handler component.  The vulnerabilities appear to have been discovered internally, and there is no indication that they have been exploited in the wild.

 

SecurityWeek reports: "Two Remote Code Execution Vulnerabilities Patched in WhatsApp"

Submitted by Anonymous on