A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Link | Tags |
---|---|
https://www.whatsapp.com/security/advisories/2021/ | vendor advisory |