Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

WhatsApp 2019

A zero-click vulnerability in WhatsApp's voice-calling infrastructure allowed a device to be compromised by a specially crafted call, even if the recipient did not answer. WhatsApp reported approximately 1,400 users were targeted during the documented attack period.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Year: 2019 · Platform: cross-platform · Vector: WhatsApp calling infrastructure
  • 02Interaction: Zero-click (no user interaction required)
  • 03CVEs: CVE-2019-3568
  • 04Discovered by: WhatsApp / Citizen Lab
  • 05Patched: WhatsApp client update, May 2019

Technical Description

A buffer overflow in the WhatsApp VOIP stack allowed remote code execution when processing a crafted call setup, before the user interacted with the call.

Zero-Click Relevance

Zero-Click Vector

A defining zero-click case: exploitation began without the target clicking a link or answering the call. It became the basis of WhatsApp's lawsuit against NSO Group.

Vulnerabilities

CVEStatus
CVE-2019-3568Patched

Attribution

WhatsApp attributed the attack to NSO Group; later litigation addressed NSO's role.

FORENSICALLY CONFIRMED

“WhatsApp 2019 is a Pegasus exploit.”

WhatsApp attributed the attack to NSO Group; later litigation addressed NSO's role.

META-2019-05

What NSO Group Says

NSO Group disputed aspects of the allegations and asserted sovereign immunity defenses, which courts ultimately rejected.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more