CVE-2018-6350
Status: ModifiedCritical (9.8)—
An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.69%
- Percentile among all scored CVEs: 76
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-125
- CWE-125
References
Raw JSON (NVD)
Show
{
"id": "CVE-2018-6350",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-assign@fb.com",
"affectedData": [
{
"vendor": "Facebook",
"product": "WhatsApp for Android",
"versions": [
{
"status": "affected",
"version": "2.18.276"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.18.276",
"versionType": "custom"
}
]
},
{
"vendor": "Facebook",
"product": "WhatsApp Business for Android",
"versions": [
{
"status": "affected",
"version": "2.18.99"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.18.99",
"versionType": "custom"
}
]
},
{
"vendor": "Facebook",
"product": "WhatsApp for iOS",
"versions": [
{
"status": "affected",
"version": "2.18.100.6"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.18.100.6",
"versionType": "custom"
}
]
},
{
"vendor": "Facebook",
"product": "WhatsApp Business for iOS",
"versions": [
{
"status": "affected",
"version": "2.18.100.2"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.18.100.2",
"versionType": "custom"
}
]
},
{
"vendor": "Facebook",
"product": "WhatsApp for Windows Phone",
"versions": [
{
"status": "affected",
"version": "2.18.224"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.18.224",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-06-14T17:29:02.283",
"references": [
{
"url": "http://www.securityfocus.com/bid/108803",
"source": "cve-assign@fb.com"
},
{
"url": "https://www.facebook.com/security/advisories/cve-2018-6350/",
"tags": [
"Third Party Advisory"
],
"source": "cve-assign@fb.com"
},
{
"url": "http://www.securityfocus.com/bid/108803",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.facebook.com/security/advisories/cve-2018-6350/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve-assign@fb.com",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224."
},
{
"lang": "es",
"value": "Fue posible una lectura fuera de límites en WhatsApp debido a un análisis incorrecto de los encabezados de extensión RTP. Este problema afecta a WhatsApp para Android anterior a versión 2.18.276, WhatsApp Business para Android anterior a versión 2.18.99, WhatsApp para iOS anterior a versión 2.18.100.6, WhatsApp Business para iOS anterior a versión 2.18.100.2 y WhatsApp para Windows Phone anterior a versión 2.18. 224."
}
],
"lastModified": "2026-06-17T02:01:43.323",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "139F635A-0B95-4E79-BE42-1EF2CE5A8F40",
"versionEndExcluding": "2.18.99"
},
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "441C5C11-D968-4BC4-ADA8-E16B5174B8DB",
"versionEndExcluding": "2.18.100.6"
},
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows_phone:*:*",
"vulnerable": true,
"matchCriteriaId": "CF68727A-1D7F-4A59-A35B-B4D1B3F5929F",
"versionEndExcluding": "2.18.224"
},
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "E32A40F1-0603-4B25-AD54-BE1031AFEB8B",
"versionEndExcluding": "2.18.100.2"
},
{
"criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "9C4BF3FF-4969-4E1F-A53C-6034EC7398D5",
"versionEndExcluding": "2.18.276"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-assign@fb.com"
}