Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2019-3568
Facebook WhatsApp for Android — Meta Platforms WhatsApp
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .3008 98.2 YES
AFFECTED
Product Versions Fixed
WhatsApp for Android 2.19.134 – —
WhatsApp Business for Android 2.19.44 – —
WhatsApp for iOS 2.19.51 – —
WhatsApp Business for iOS 2.19.51 – —
WhatsApp for Windows Phone 2.18.348 – —
WhatsApp for Tizen 2.18.15 – —
TIMELINE
Jan 2 Reserved by facebook
May 14 Published (CNA: facebook)
Apr 19 Added to CISA KEV, remediation due 2022-05-10
Description
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 2, 2019 | Reserved | Reserved by facebook |
| May 14, 2019 | Published | Published (CNA: facebook) |
| April 19, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-05-10 |
Affected
Affected products and packages — 6 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Facebook | WhatsApp for Android | — | 2.19.134 | — |
| Facebook | WhatsApp Business for Android | — | 2.19.44 | — |
| Facebook | WhatsApp for iOS | — | 2.19.51 | — |
| Facebook | WhatsApp Business for iOS | — | 2.19.51 | — |
| Facebook | WhatsApp for Windows Phone | — | 2.18.348 | — |
| Facebook | WhatsApp for Tizen | — | 2.18.15 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2019-3568 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.