WhatsApp Reveals Critical Vulnerabilities in Older App Versions That Let Attacker Exploit Phones via Video Call

WhatsApp bug would let an attacker exploit integer overflow, after which they can get access to execute their own code on a victim's smartphone.

Advertisement
By Agencies | Updated: 28 September 2022 19:29 IST
Highlights
  • Details regarding the vulnerability were revealed in a September update
  • CVE-2022-36934 was given a severity score of 9.8 out of 10
  • Head of WhatsApp's India payment business has quit
WhatsApp Reveals Critical Vulnerabilities in Older App Versions That Let Attacker Exploit Phones via Video Call

WhatsApp, in an update, shared a detailed issue related to vulnerability CVE-2022-36934

WhatsApp, Meta's instant messaging and calling service, has published details of a 'critical' vulnerability that has been patched in a newer version of the app but might still affect older installed versions that have not been updated.

The details regarding the vulnerability were revealed in a September update of WhatsApp's page on security advisories affecting the app and came to light on September 23.

WhatsApp, in the update, shared a detailed issue related to vulnerability CVE-2022-36934, according to which "an integer overflow in WhatsApp for Android prior to v2.22.16.12, Business for Android prior to v2.22.16.12, iOS prior to v2.22.16.12, Business for iOS prior to v2.22.16.12 could result in remote code execution in an established video call."

According to the details, the bug would let an attacker exploit integer overflow, after which they can get access to execute their own code on a victim's smartphone through a specially crafted video call.

Advertisement

This vulnerability has been given a severity score of 9.8 out of 10 on the CVE scale.

In the same security advisory update, WhatsApp also explained another vulnerability, CVE-2022-27492. According to the social media company, "an integer underflow in WhatsApp for Android prior to v2.22.16.2, WhatsApp for iOS v2.22.15.9 could have caused remote code execution when receiving a crafted video file."

Advertisement

This said, the bug would let attackers execute the code on the victim's smartphone using a malicious video file. The vulnerability was scored 7.8 out of 10.

In an India-related development for the social media platform, the head of WhatsApp's India payment business, Manesh Mahatme, has quit after more than a year with the Meta Platforms-owned company to join Amazon India, a source told Reuters on Thursday.

Advertisement

Mahatme's exit comes at a critical time for WhatsApp, which is seeking to ramp up its payments service in a highly competitive market and lock horns with more established players such as Alphabet's Google Pay, Ant Group-backed Paytm and Walmart's PhonePe.

During his stint at WhatsApp Pay, the company won regulatory approval to more than double its payments offering to 100 million users in India, its biggest market with more than half a billion users overall.


Missed Apple's WWDC 2022? We discuss every major announcement on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.

 

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: whatsapp, whatsapp bug, meta
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Kaalidhar Laapata, Thug Life, The Good Wife, and More
  2. Oppo Reno 14 Pro 5G Launched in India Alongside Reno 14 5G: See Price
  3. Honor Watch 5 Ultra With eSIM Support, ECG Tracking Launched
  4. Samsung Galaxy Z Fold 7 Hands-On Images Suggest It Might Sport This Design
  5. Tecno Pova 7 5G Series Launching Today: All You Need to Know
  6. Boult FluidX, FluidX Pro Debut in India With Up to 70 Hours Battery Life
  7. Oppo Reno 14 Pro First Impressions
  8. Tecno Spark 40 Pro+, Spark 40 Pro and Spark 40 Launched: All Details
  9. OPPO K13x 5G Overview: The Strongest Warrior in the Durability Battlefield
  1. Samsung Galaxy Z Fold 7 Design Spotted in Leaked Hands-On Images Ahead of July 9 Launch
  2. iPhone 17 Pro Max Could Get a Battery Upgrade Over Its Predecessor; May ‘Reach’ 5,000mAh Capacity
  3. Apple MacBook Pro With M5 Chip to Launch This Year; 15 Mac Computers in Development: Report
  4. Tecno Pova 7 5G Series Launching Today: Expected Features and Specifications
  5. A Planet with a Death Wish: How HIP 67522 b Is Forcing Its Star to Explode
  6. Webb Telescope Spots Possible Jellyfish Galaxy 12 Billion Light-Years Away
  7. Mars Dust Devils May Spark Lightning, Might Pose Risks to Rovers: Study
  8. NASA's Perseverance Grinds Into ‘Weird’ Martian Rock to Uncover Signs of Ancient Habitability
  9. Radio Observations in Chamaeleon Cloud Reveal Five Young Stars, Including a Binary System
  10. Paramasivan Fathima OTT Release Date: When and Where to Watch Tamil Horror Thriller Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.