Skip to content

WhatsApp Patches Critical RCE Vulnerabilities, Qualys Offers Detection & Patch Management

WhatsApp's recent security patches fix critical RCE bugs. Qualys VMDR Mobile helps organizations identify affected devices and manage patches.

In this image there is person using a mobile phone, on the screen there are few apps and a number...
In this image there is person using a mobile phone, on the screen there are few apps and a number is written on the piece of paper and attached to the phone and the phone is on the table.

WhatsApp Patches Critical RCE Vulnerabilities, Qualys Offers Detection & Patch Management

WhatsApp has recently addressed two critical remote code execution (RCE) vulnerabilities, CVE-2022-27492 and CVE-2022-36934, affecting various versions of its platforms. To assist organizations in identifying affected devices, Qualys has developed Qualys VMDR Mobile.

The first vulnerability, CVE-2022-27492, with a CVSSv3 base score of 7.8, impacts WhatsApp for Android v2.22.16.2 and WhatsApp for iOS v2.22.15.9. Exploiting this vulnerability could enable an attacker to install malware on the device. WhatsApp has since released a patch to fix this issue.

The second vulnerability, CVE-2022-36934, is more severe with a CVSSv3 base score of 9.8. It affects assets running WhatsApp for Android prior to v2.22.16.12, WhatsApp Business for Android prior to v2.22.16.12, WhatsApp for iOS prior to v2.22.16.12, and WhatsApp Business for iOS prior to v2.22.16.12. WhatsApp has also patched this vulnerability.

Qualys VMDR Mobile can help organizations identify assets running WhatsApp with the impacted versions. It also provides patch orchestration for Android devices. Qualys offers a free trial for 30 days to assist organizations in detecting vulnerabilities and monitoring critical device settings.

With the recent patches, WhatsApp has addressed critical and high-severity vulnerabilities affecting its platforms. Organizations can utilize Qualys VMDR Mobile to identify affected devices and manage patches, ensuring the security of their communications.

Read also:

Latest