CVE-2025-30259
The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 19, 2025
- Published Date
- March 19, 2025
- Last Updated
- March 20, 2025
- Vendor
- Meta
- Product
- WhatsApp cloud service
- Description
- The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.
CVSS Scores
CVSS v3.1
3.5 - LOW
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
SSVC Information
- Exploitation
- none
- Technical Impact
- partial
Exploit Status
- Exploited in the Wild
- Yes (added 2025-03-20 00:00:00 UTC) Source
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2025-03-20 00:00:00 UTC |