[ RECORD YEAR ]2019
🇺🇸 United StatesVoice Plane CVE-2019-3568

WhatsApp Zero-Click Voice Call Exploit (Pegasus / CVE-2019-3568)

An attacker only had to ring a WhatsApp call. NSO Group's Pegasus implant was delivered to ~1,400 targets through a buffer overflow in the VoIP call stack — the victim never had to answer, and the missed-call log was the only trace.

THREAT SEVERITY
9.4 / 10
Target TechnologyWhatsApp VoIP Call Signaling (Proprietary over QUIC/TCP)
OSI Network LayerLayer 5/7 / Session & VoIP Call Signaling
Threat Actor / AttributionNSO Group (Pegasus)
Protocol StandardVoIP call signaling (proprietary)

02Deep-Dive Technical Analysis

CVE-2019-3568 was a buffer overflow in WhatsApp's VoIP stack that allowed remote code execution via a specially crafted series of SDP-like session initiation packets sent to the target's WhatsApp number. Facebook's advisory confirmed exploitation "against a number of users" including human rights activists, journalists, and lawyers, and Citizen Lab correlation showed at least 100+ cases across 20+ countries with direct NSO Pegasus infrastructure overlap. The attack class is significant because it exploited the voice signaling plane, not content delivery: the malicious payload arrived in call setup messages processed by the client before any user interaction. It was fixed server-side in May 2019, with Facebook pushing an out-of-band client update.

03Vulnerability & Exploit Flow

Exploit Vector

Buffer overflow in VoIP call processing yields RCE from call setup alone — zero user interaction required.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Patch VoIP signaling clients out-of-band (server-side forced updates), fuzz call setup parsers continuously, isolate VoIP stacks with memory-safe rewrites or sandboxing, and treat missed-call metadata as a forensic indicator in targeted-attack response.

05Security Impact & Geopolitical Consequence

The incident established that zero-click attacks over voice infrastructure were practical at consumer scale, accelerating both the mobile security community's focus on VoIP stack hardening and the "Pegasus era" of NSO Group revelations. It triggered a US federal lawsuit (WhatsApp v. NSO Group), a landmark court ruling that NSO is not immune as a foreign-state agent, and sanctions/designations against commercial spyware vendors. For operators it proved that OTT voice applications carry the same signaling-exploit risk historically associated with SS7 — a single malformed call setup can be a full implant delivery vehicle.

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators