HomeCyber SecurityWhatsApp Points Emergency Replace for Zero-Click on Exploit Focusing on iOS and...

WhatsApp Points Emergency Replace for Zero-Click on Exploit Focusing on iOS and macOS Units


Aug 30, 2025Ravie LakshmananZero-Day / Vulnerability

WhatsApp Points Emergency Replace for Zero-Click on Exploit Focusing on iOS and macOS Units

WhatsApp has addressed a safety vulnerability in its messaging apps for Apple iOS and macOS that it mentioned could have been exploited within the wild at the side of a lately disclosed Apple flaw in focused zero-day assaults.

The vulnerability, CVE-2025-55177 (CVSS rating: 8.0), pertains to a case of inadequate authorization of linked gadget synchronization messages. Inside researchers on the WhatsApp Safety Workforce have been credited with discovering and rerating the bug.

The Meta-owned firm mentioned the problem “may have allowed an unrelated person to set off processing of content material from an arbitrary URL on a goal’s gadget.”

Cybersecurity

The flaw impacts the next variations –

  • WhatsApp for iOS previous to model 2.25.21.73
  • WhatsApp Enterprise for iOS model 2.25.21.78, and
  • WhatsApp for Mac model 2.25.21.78

It additionally assessed that the shortcoming could have been chained with CVE-2025-43300, a vulnerability affecting iOS, iPadOS, and macOS, as a part of a classy assault in opposition to particular focused customers.

CVE-2025-43300 was disclosed by Apple final week as having been weaponized in an “extraordinarily refined assault in opposition to particular focused people.”

The vulnerability in query is an out-of-bounds write vulnerability within the ImageIO framework that would end in reminiscence corruption when processing a malicious picture.

Donncha Ó Cearbhaill, head of the Safety Lab at Amnesty Worldwide, mentioned WhatsApp has notified an unspecified variety of people that they imagine had been focused by a sophisticated adware marketing campaign previously 90 days utilizing CVE-2025-55177.

Within the alert despatched to the focused people, WhatsApp has additionally really helpful performing a full gadget manufacturing unit reset and holding their working system and the WhatsApp app up-to-date for optimum safety. It is presently not identified who, or which adware vendor, is behind the assaults.

Identity Security Risk Assessment

Ó Cearbhaill described the pair of vulnerabilities as a “zero-click” assault, which means it doesn’t require any person interplay, akin to clicking a hyperlink, to compromise their gadget.

“Early indications are that the WhatsApp assault is impacting each iPhone and Android customers, civil society people amongst them,” Ó Cearbhaill mentioned. “Authorities adware continues to pose a menace to journalists and human rights defenders.”

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments