CVE-2020-1908

Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*

History

21 Nov 2024, 05:11

Type Values Removed Values Added
References () https://www.whatsapp.com/security/advisories/2020/ - Vendor Advisory () https://www.whatsapp.com/security/advisories/2020/ - Vendor Advisory

Information

Published : 2020-11-03 20:15

Updated : 2024-11-21 05:11


NVD link : CVE-2020-1908

Mitre link : CVE-2020-1908

CVE.ORG link : CVE-2020-1908


JSON object : View

Products Affected

whatsapp

  • whatsapp_business
  • whatsapp
CWE
CWE-285

Improper Authorization

CWE-552

Files or Directories Accessible to External Parties