PatchSiren

Meta Platforms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Meta Platforms CVE published 2025-09-02

CVE-2025-55177

CVE-2025-55177 is a Meta Platforms WhatsApp incorrect authorization vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-09-02. Because it is on the KEV catalog, defenders should treat it as actively important and prioritize vendor-guided mitigation and patching. The supplied corpus does not include a CVSS score or deeper technical impact details, so the safest response is [truncated]

Known exploited Meta Platforms CVE published 2022-05-23

CVE-2019-18426

CVE-2019-18426 is a cross-site scripting (XSS) vulnerability affecting Meta Platforms' WhatsApp and is listed in CISA's Known Exploited Vulnerabilities catalog. The supplied timeline shows it was published and added to KEV on 2022-05-23, with remediation due by 2022-06-13. Defenders should treat it as a patch-priority issue and verify that all WhatsApp installations follow vendor update guidance.

Known exploited Meta Platforms CVE published 2022-04-19

CVE-2019-3568

CVE-2019-3568 is identified in the provided corpus as a WhatsApp VOIP stack buffer overflow and is listed by CISA in its Known Exploited Vulnerabilities catalog. Because CISA classifies it as known exploited, it should be treated as an urgent remediation item and addressed using vendor update guidance as soon as possible.