PT-2025-35227 · Meta · Whatsapp For Ios+2
Published
2025-08-29
·
Updated
2026-03-15
·
CVE-2025-55177
CVSS v2.0
5.5
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WhatsApp versions prior to 2.25.21.73
WhatsApp Business versions prior to 2.25.21.78
WhatsApp for Mac versions prior to 2.25.21.78
Description
WhatsApp contained a critical authorization flaw in the handling of linked device synchronization messages. This flaw allowed an attacker to trigger the processing of content from an arbitrary URL on a target’s device without any user interaction, a so-called “zero-click” exploit. The vulnerability was exploited in targeted attacks, potentially in conjunction with an Apple OS flaw, and may have impacted fewer than 200 users. The attacks were reported to have targeted civil society members. The flaw stemmed from incomplete authorization during the synchronization process, enabling malicious data to be processed by the application.
Recommendations
Update WhatsApp to version 2.25.21.73 or later.
Update WhatsApp Business to version 2.25.21.78 or later.
Update WhatsApp for Mac to version 2.25.21.78 or later.
Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Whatsapp Business For Ios
Whatsapp For Mac
Whatsapp For Ios