I'm glad it's fixed now. https://www.facebook.com/security/advisories/cve-2019-11931
[0] https://nakedsecurity.sophos.com/2019/11/20/update-whatsapp-...
[1] https://context-cdn.washingtonpost.com/notes/prod/default/do...
[2] https://www.facebook.com/security/advisories/cve-2019-3568
[3] https://arstechnica.com/information-technology/2019/05/whats...
Any rough theories on how this sort of thing can happen? How can an app go from parsing metadata to executing foreign code?