PT-2025-35227 · Meta · Whatsapp For Mac +2
Published
2025-08-29
·
Updated
2025-08-30
·
CVE-2025-55177
5.4
Medium
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
**Name of the Vulnerable Software and Affected Versions:**
WhatsApp for iOS versions prior to 2.25.21.73
WhatsApp Business for iOS version prior to 2.25.21.78
WhatsApp for Mac version prior to 2.25.21.78
**Description:**
A critical zero-click flaw exists in WhatsApp’s linked device synchronization feature due to incomplete authorization. This flaw allows attackers to trigger the processing of content from arbitrary URLs on a target device without any user interaction. The vulnerability was exploited in targeted attacks, potentially in conjunction with an Apple OS-level flaw. Fewer than 200 individuals were reportedly affected during a 90-day campaign, including members of civil society. The flaw stems from insufficient authorization in WhatsApp’s linked device sync feature.
**Recommendations:**
Update WhatsApp for iOS to version 2.25.21.73 or later.
Update WhatsApp Business for iOS to version 2.25.21.78 or later.
Update WhatsApp for Mac to version 2.25.21.78 or later.
Fix
Related Identifiers
Affected Products
References · 51
- https://nvd.nist.gov/vuln/detail/CVE-2025-55177 · Security Note
- https://twitter.com/MohdMaskati/status/1961514557278474308 · Twitter Post
- https://twitter.com/oxhak/status/1961662822590337474 · Twitter Post
- https://twitter.com/SentinelLinkHQ/status/1961903282999132353 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1961517413523927171 · Twitter Post
- https://facebook.com/security/advisories/cve-2025-55177 · Note
- https://whatsapp.com/security/advisories/2025 · Note
- https://twitter.com/grok/status/1961473002803167543 · Twitter Post
- https://twitter.com/billmarczak/status/1961457322133524725 · Twitter Post
- https://reddit.com/r/KibernetinisSaugumas/comments/1n3xiom/whatsapp_0dienos_pa%C5%BEeid%C5%BEiamumas · Reddit Post
- https://twitter.com/kanada_vaibhav/status/1961508045022007362 · Twitter Post
- https://twitter.com/the_yellow_fall/status/1961488832492458149 · Twitter Post
- https://t.me/true_secator/7379 · Telegram Post
- https://twitter.com/XSSentials_4u/status/1961630360544137356 · Twitter Post
- https://t.me/S_E_Reborn/5863 · Telegram Post