WhatsApp 2019
A zero-click vulnerability in WhatsApp's voice-calling infrastructure allowed a device to be compromised by a specially crafted call, even if the recipient did not answer. WhatsApp reported approximately 1,400 users were targeted during the documented attack period.
- 01Year: 2019 · Platform: cross-platform · Vector: WhatsApp calling infrastructure
- 02Interaction: Zero-click (no user interaction required)
- 03CVEs: CVE-2019-3568
- 04Discovered by: WhatsApp / Citizen Lab
- 05Patched: WhatsApp client update, May 2019
Technical Description
A buffer overflow in the WhatsApp VOIP stack allowed remote code execution when processing a crafted call setup, before the user interacted with the call.
Zero-Click Relevance
A defining zero-click case: exploitation began without the target clicking a link or answering the call. It became the basis of WhatsApp's lawsuit against NSO Group.
Vulnerabilities
| CVE | Status |
|---|---|
| CVE-2019-3568 | Patched |
Attribution
WhatsApp attributed the attack to NSO Group; later litigation addressed NSO's role.
“WhatsApp 2019 is a Pegasus exploit.”
WhatsApp attributed the attack to NSO Group; later litigation addressed NSO's role.
What NSO Group Says
NSO Group disputed aspects of the allegations and asserted sovereign immunity defenses, which courts ultimately rejected.
