CVE-2019-3566

MEDIUM

WhatsApp for Android 2.19.52-2.19.103 & Business 2.19.22-2.19.38 - Unauthenticated Message Recovery

Title source: llm
STIX 2.1

Description

A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.facebook.com/security/advisories/cve-2019-3566

Scores

CVSS v3 5.9
EPSS 0.0107
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284
Status published
Products (3)
whatsapp/whatsapp 2.19.52
whatsapp/whatsapp 2.19.54 - 2.19.103
whatsapp/whatsapp_business 2.19.22 - 2.19.38
Published May 10, 2019
Tracked Since Feb 18, 2026