PT-2025-35227 · Meta · Whatsapp For Mac +2

Published

2025-08-29

·

Updated

2025-08-30

·

CVE-2025-55177

CVSS v3.1
5.4
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

**Name of the Vulnerable Software and Affected Versions:**

WhatsApp for iOS versions prior to 2.25.21.73

WhatsApp Business for iOS version prior to 2.25.21.78

WhatsApp for Mac version prior to 2.25.21.78

**Description:**

A critical zero-click flaw exists in WhatsApp’s linked device synchronization feature due to incomplete authorization. This flaw allows attackers to trigger the processing of content from arbitrary URLs on a target device without any user interaction. The vulnerability was exploited in targeted attacks, potentially in conjunction with an Apple OS-level flaw. Fewer than 200 individuals were reportedly affected during a 90-day campaign, including members of civil society. The flaw stems from insufficient authorization in WhatsApp’s linked device sync feature.

**Recommendations:**

Update WhatsApp for iOS to version 2.25.21.73 or later.

Update WhatsApp Business for iOS to version 2.25.21.78 or later.

Update WhatsApp for Mac to version 2.25.21.78 or later.

Fix

Related Identifiers

CVE-2025-55177

Affected Products

Whatsapp Business For Ios
Whatsapp For Mac
Whatsapp For Ios