Learn about CVE-2020-1902 affecting WhatsApp for Android and WhatsApp Business, allowing exposure of sensitive information to unauthorized parties. Find mitigation steps and prevention measures.
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.
Understanding CVE-2020-1902
This CVE impacts WhatsApp for Android and WhatsApp Business for Android, potentially exposing sensitive information.
What is CVE-2020-1902?
CVE-2020-1902 involves the exposure of sensitive information to an unauthorized actor, specifically occurring during searches on highly forwarded messages on WhatsApp for Android and WhatsApp Business.
The Impact of CVE-2020-1902
Technical Details of CVE-2020-1902
This section provides detailed technical insights into the vulnerability.
Vulnerability Description
The vulnerability allows users running specific versions of WhatsApp for Android and WhatsApp Business for Android to unintentionally share information with unauthorized parties while conducting message searches.
Affected Systems and Versions
Exploitation Mechanism
Users conducting searches on highly forwarded messages between the specified versions could unknowingly transmit data to the Google service over plain HTTP.
Mitigation and Prevention
Protective measures and best practices to mitigate the impact of CVE-2020-1902.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates