VULNERABILITY INTELLIGENCE
CVE-2020-1908
CVSS score4.6 MEDIUM
EPSS probability0.29%
CISA KEVNot currently listed
Published2020-11-03
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Description
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact with the WhatsApp application even after the phone was locked.
Weakness classification
- CWE-285: Improper Authorization
- CWE-552: Files or Directories Accessible to External Parties
Primary references
- cve-assign@fb.com — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory