CVE-2025-55177

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78,...

Basic Information

CVE State
PUBLISHED
Reserved Date
August 08, 2025
Published Date
August 29, 2025
Last Updated
February 26, 2026
Vendor
Facebook
Product
WhatsApp Desktop for Mac, WhatsApp Business for iOS, WhatsApp for iOS
Description
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Tags
cisa

CVSS Scores

CVSS v3.1

5.4 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:39:48 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:39:48 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel