CVE-2021-24035

CRITICAL

WhatsApp and WhatsApp Business < 2.21.8.13 - Path Traversal via Archive Extraction

Title source: llm
STIX 2.1

Description

A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.whatsapp.com/security/advisories/2021/

Scores

CVSS v3 9.1
EPSS 0.0113
EPSS Percentile 62.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-22 CWE-23
Status published
Products (2)
whatsapp/whatsapp < 2.21.8.13
whatsapp/whatsapp_business < 2.21.8.13
Published Jun 11, 2021
Tracked Since Feb 18, 2026