CVE-2019-3566
MEDIUMWhatsApp for Android 2.19.52-2.19.103 & Business 2.19.22-2.19.38 - Unauthenticated Message Recovery
Title source: llmDescription
A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.facebook.com/security/advisories/cve-2019-3566
Scores
CVSS v3
5.9
EPSS
0.0107
EPSS Percentile
60.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-284
Status
published
Products (3)
whatsapp/whatsapp
2.19.52
whatsapp/whatsapp
2.19.54 - 2.19.103
whatsapp/whatsapp_business
2.19.22 - 2.19.38
Published
May 10, 2019
Tracked Since
Feb 18, 2026