The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 20 Mar 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL. | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-19T00:00:00.000Z
Updated: 2025-03-20T20:36:29.389Z
Reserved: 2025-03-19T00:00:00.000Z
Link: CVE-2025-30259

Updated: 2025-03-20T20:36:25.533Z

Status : Received
Published: 2025-03-20T00:15:13.780
Modified: 2025-03-20T00:15:13.780
Link: CVE-2025-30259

No data.