Vulnerability Description
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| < 2.20.185 |
Related Weaknesses (CWE)
References
- https://www.whatsapp.com/security/advisories/2020/Vendor Advisory
- https://www.whatsapp.com/security/advisories/2020/Vendor Advisory
FAQ
What is CVE-2020-1905?
CVE-2020-1905 is a vulnerability with a CVSS score of 3.3 (LOW). Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen t...
How severe is CVE-2020-1905?
CVE-2020-1905 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1905?
Check the references section above for vendor advisories and patch information. Affected products include: Whatsapp Whatsapp.