PT-2025-35227 · Meta · Whatsapp For Ios +2
Published
2025-08-29
·
Updated
2025-10-17
·
CVE-2025-55177
CVSS v2.0
5.5
5.5
Medium
Base vector | Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WhatsApp versions prior to 2.25.21.73
WhatsApp Business versions prior to 2.25.21.78
WhatsApp for Mac versions prior to 2.25.21.78
Description
WhatsApp was found to have an incomplete authorization issue in linked device synchronization messages. This flaw could allow an unrelated user to trigger the processing of content from an arbitrary URL on a target’s device without any user interaction, a so-called 'zero-click' exploit. This vulnerability was exploited in targeted attacks, potentially in combination with an Apple OS-level flaw. Fewer than 200 users were reportedly affected during a 90-day campaign, with targets including journalists and human rights activists. The flaw stems from an incorrect authorization in the process of synchronizing linked devices, enabling attackers to send malicious data via these messages. The exploitation of this vulnerability does not require any action from the user. The API endpoint is not explicitly mentioned in the provided data.
Recommendations
Update WhatsApp to version 2.25.21.73 or later.
Update WhatsApp Business to version 2.25.21.78 or later.
Update WhatsApp for Mac to version 2.25.21.78 or later.
Review and remove any unknown linked devices.
Consider a factory reset if you believe you were targeted.
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-10994
CVE-2025-55177
Affected Products
Whatsapp Business For Ios
Whatsapp For Mac
Whatsapp For Ios
References · 191
- https://bdu.fstec.ru/vul/2025-10994 · Security Note
- https://facebook.com/security/advisories/cve-2025-55177 · Vendor Advisory
- https://whatsapp.com/security/advisories/2025 · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-55177 · Security Note
- https://twitter.com/The_Cyber_News/status/1963231040077537461 · Twitter Post
- https://twitter.com/the_yellow_fall/status/1961488832492458149 · Twitter Post
- https://twitter.com/FindSecCyber/status/1961665955471241321 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1961517413523927171 · Twitter Post
- https://twitter.com/TechNadu/status/1961807242497597692 · Twitter Post
- https://twitter.com/cybrhoodsentinl/status/1961779083001627064 · Twitter Post
- https://twitter.com/CyberDigests/status/1962981271233073603 · Twitter Post
- https://reddit.com/r/TechNadu/comments/1n77weu/cisa_adds_whatsapp_tplink_flaws_to_kev_catalog · Reddit Post
- https://twitter.com/ManMotasem/status/1964678835502555534 · Twitter Post
- https://twitter.com/BaselineITC/status/1977825775756943372 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1n3xv8j/top_10_trending_cves_30082025 · Reddit Post