Rewterz
Rewterz Threat Advisory – CVE-2021-29154 – Linux Kernel privilege escalation
April 9, 2021
Rewterz
Rewterz Threat Alert – AZORult Malware – Active IOCs
April 9, 2021

Rewterz Threat Advisory – CVE-2021-24027 – WhatsApp for Android and WhatsApp Business for Android information disclosure

Severity

Medium

Analysis Summary

CVE-2021-24027

A local authenticated attacker is acquiring informative data caused by a cache configuration issue. Attacker is sending a specially-crafted request attacker could exploit this vulnerability in order to gain cached TLS information.

Impact

Unauthorized Access

Affected Vendors

WhatsApp

Affected Products

  • WhatsApp for Android 2.21
  • WhatApp Business for Andorid 2.21

Remediation

Refer to WhatsApp Security Advisories for patch, upgrade or suggested workaround information. See References.

WhatsApp Security Advisories