WhatsApp Zero-Click Voice Call Exploit (Pegasus / CVE-2019-3568)
An attacker only had to ring a WhatsApp call. NSO Group's Pegasus implant was delivered to ~1,400 targets through a buffer overflow in the VoIP call stack — the victim never had to answer, and the missed-call log was the only trace.
02Deep-Dive Technical Analysis
CVE-2019-3568 was a buffer overflow in WhatsApp's VoIP stack that allowed remote code execution via a specially crafted series of SDP-like session initiation packets sent to the target's WhatsApp number. Facebook's advisory confirmed exploitation "against a number of users" including human rights activists, journalists, and lawyers, and Citizen Lab correlation showed at least 100+ cases across 20+ countries with direct NSO Pegasus infrastructure overlap. The attack class is significant because it exploited the voice signaling plane, not content delivery: the malicious payload arrived in call setup messages processed by the client before any user interaction. It was fixed server-side in May 2019, with Facebook pushing an out-of-band client update.
03Vulnerability & Exploit Flow
Buffer overflow in VoIP call processing yields RCE from call setup alone — zero user interaction required.
04Recommended Defense & Mitigation Protocol
Patch VoIP signaling clients out-of-band (server-side forced updates), fuzz call setup parsers continuously, isolate VoIP stacks with memory-safe rewrites or sandboxing, and treat missed-call metadata as a forensic indicator in targeted-attack response.
05Security Impact & Geopolitical Consequence
The incident established that zero-click attacks over voice infrastructure were practical at consumer scale, accelerating both the mobile security community's focus on VoIP stack hardening and the "Pegasus era" of NSO Group revelations. It triggered a US federal lawsuit (WhatsApp v. NSO Group), a landmark court ruling that NSO is not immune as a foreign-state agent, and sanctions/designations against commercial spyware vendors. For operators it proved that OTT voice applications carry the same signaling-exploit risk historically associated with SS7 — a single malformed call setup can be a full implant delivery vehicle.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.