A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have caused the recipient of a sticker message containing deliberately malformed data to load an image from a sender-controlled URL without user interaction.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1890
Reference (s):
- https://www.whatsapp.com/security/advisories/2020
- URL: https://www.whatsapp.com/security/advisories/2020

