CVE-2021-24027
NixOS vulnerability analysis and mitigation

Overview

A cache configuration vulnerability (CVE-2021-24027) was discovered in WhatsApp for Android and WhatsApp Business for Android versions prior to v2.21.4.18. The vulnerability allowed third parties with access to the device's external storage to read cached TLS material (MITRE).

Technical details

The vulnerability leverages Chrome's support for content providers in Android through the 'content://' URL scheme and involves a same-origin policy bypass in the browser (CVE-2020-6516). The flaw allows attackers to send specially-crafted HTML files to victims over WhatsApp, which when opened in the browser, could execute malicious code. The vulnerability exposes TLS session key details stored in an unprotected external storage area, making them accessible to any app with read/write permissions (Hacker News).

Impact

The vulnerability could allow attackers to compromise WhatsApp communications, achieve remote code execution on the victim's device, and extract Noise protocol keys used for end-to-end encryption in user communications. Additionally, attackers could access sensitive information stored in the external storage area, including TLS session materials (Hacker News).

Exploitability

The exploit requires an attacker to lure the victim into opening an HTML document attachment. When opened in Chrome through WhatsApp, the attacker's JavaScript code could steal stored TLS session keys. This vulnerability affects devices running Android versions up to and including Android 9 (Hacker News).

Mitigation and workarounds

Users are recommended to update to WhatsApp version 2.21.4.18 or later to mitigate the risk. Google has also introduced 'scoped storage' in Android 10 as a defensive measure, which provides isolated storage areas for each app, preventing unauthorized access from other applications (Hacker News).

Community reactions

WhatsApp has confirmed that the end-to-end encryption continues to work as intended and users' messages remain secure. The company acknowledged the researchers' findings and implemented improvements to protect users when visiting malicious websites on Chrome (Hacker News).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management