PT-2025-35227 · Meta · Whatsapp For Mac +2
Published
2025-08-29
·
Updated
2025-09-01
·
CVE-2025-55177
5.4
Medium
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
**Name of the Vulnerable Software and Affected Versions:**
WhatsApp for iOS versions prior to 2.25.21.73
WhatsApp Business for iOS version prior to 2.25.21.78
WhatsApp for Mac version prior to 2.25.21.78
**Description:**
A critical zero-click vulnerability exists in WhatsApp’s linked device synchronization feature due to incomplete authorization. This flaw allows attackers to trigger the processing of content from arbitrary URLs on a target device without any user interaction. The vulnerability was exploited in targeted attacks, potentially in combination with an Apple OS-level vulnerability. Fewer than 200 individuals were reportedly affected during a 90-day campaign, including members of civil society. The attack involved sending malicious sync messages to compromise devices.
**Recommendations:**
Update WhatsApp to version 2.25.21.73 or later on iOS.
Update WhatsApp Business to version 2.25.21.78 or later on iOS.
Update WhatsApp to version 2.25.21.78 or later on macOS.
Fix
Related Identifiers
Affected Products
References · 66
- https://nvd.nist.gov/vuln/detail/CVE-2025-55177 · Security Note
- https://twitter.com/z3nch4n/status/1961794813248082360 · Twitter Post
- https://facebook.com/security/advisories/cve-2025-55177 · Note
- https://twitter.com/cybrhoodsentinl/status/1961781204459680061 · Twitter Post
- https://twitter.com/officer_cia/status/1961470777972420948 · Twitter Post
- https://twitter.com/CVEnew/status/1961463470584672430 · Twitter Post
- https://twitter.com/not2cleverdotme/status/1962337836038058257 · Twitter Post
- https://twitter.com/techawarenepal/status/1962054232313667728 · Twitter Post
- https://twitter.com/TechNadu/status/1961807242497597692 · Twitter Post
- https://twitter.com/techinfradaily/status/1961530270596960571 · Twitter Post
- https://twitter.com/CrowdCyber_Com/status/1962170112040939985 · Twitter Post
- https://reddit.com/r/KibernetinisSaugumas/comments/1n3xiom/whatsapp_0dienos_pa%C5%BEeid%C5%BEiamumas · Reddit Post
- https://reddit.com/r/u_sork877/comments/1n3ogiw/whatsapp_corrige_vulnerabilidad_zeroday_en_ios_y · Reddit Post
- https://reddit.com/r/CVEWatch/comments/1n5kq6z/top_10_trending_cves_01092025 · Reddit Post
- https://twitter.com/SentinelLinkHQ/status/1961903282999132353 · Twitter Post