PT-2025-35227 · Meta · Whatsapp For Mac +2

Published

2025-08-29

·

Updated

2025-09-01

·

CVE-2025-55177

CVSS v3.1
5.4
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

**Name of the Vulnerable Software and Affected Versions:**

WhatsApp for iOS versions prior to 2.25.21.73

WhatsApp Business for iOS version prior to 2.25.21.78

WhatsApp for Mac version prior to 2.25.21.78

**Description:**

A critical zero-click vulnerability exists in WhatsApp’s linked device synchronization feature due to incomplete authorization. This flaw allows attackers to trigger the processing of content from arbitrary URLs on a target device without any user interaction. The vulnerability was exploited in targeted attacks, potentially in combination with an Apple OS-level vulnerability. Fewer than 200 individuals were reportedly affected during a 90-day campaign, including members of civil society. The attack involved sending malicious sync messages to compromise devices.

**Recommendations:**

Update WhatsApp to version 2.25.21.73 or later on iOS.

Update WhatsApp Business to version 2.25.21.78 or later on iOS.

Update WhatsApp to version 2.25.21.78 or later on macOS.

Fix

Related Identifiers

CVE-2025-55177

Affected Products

Whatsapp Business For Ios
Whatsapp For Mac
Whatsapp For Ios