ASA-2020-00043 – WhatsApp Desktop: Cross-Site Scripting (XSS) through a specially crafted live location message


Allele Security Alert

ASA-2020-00043

Identifier(s)

ASA-2020-00043, CVE-2019-11928

Title

Cross-Site Scripting (XSS) through a specially crafted live location message

Vendor(s)

Facebook

Product(s)

WhatsApp Desktop

Affected version(s)

WhatsApp Desktop versions before v0.3.4932

Fixed version(s)

WhatsApp Desktop version v0.3.4932

Proof of concept

Unknown

Description

An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed Cross-Site Scripting (XSS) upon clicking on a link from a specially crafted live location message.

Technical details

Unknown

Credits

Unknown

Reference(s)

WhatsApp Security Advisories
https://www.whatsapp.com/security/advisories/2020

CVE-2019-11928
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11928

CVE-2019-11928
https://nvd.nist.gov/vuln/detail/CVE-2019-11928

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: September 9, 2020

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.