CVE-2025-55177
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-55177 is an incorrect authorization vulnerability in WhatsApp's linked device synchronization mechanism that enables zero-click exploitation on Apple platforms. An unrelated, authenticated user can trigger processing of content from an arbitrary URL on a target's device without any interaction from the victim. Affected versions include WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS prior to v2.25.21.78, and WhatsApp for Mac prior to v2.25.21.78 (versions from 2.22.25.2 onward). Meta disclosed the vulnerability on August 29, 2025, and assessed that it was exploited in combination with an Apple OS-level vulnerability (CVE-2025-43300) in sophisticated attacks against specific targeted users. The CVSS v3.1 base score is 5.4 (Medium) (Meta Advisory, CISA KEV).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): WhatsApp's linked device synchronization messages were not fully authorized, allowing an unrelated user — one who is not a legitimate linked device owner — to send specially crafted synchronization messages that cause the target's device to fetch and process content from an attacker-controlled URL. The attack vector is network-based, requires low privileges (a valid WhatsApp account), and requires no user interaction, making it a true zero-click vulnerability. Exploitation was chained with CVE-2025-43300, an OS-level Apple vulnerability, to achieve more impactful outcomes such as spyware delivery. Later research revealed that malicious DNG (Digital Negative) image files sent via WhatsApp were used as the delivery mechanism to trigger the flaw, with the image parser processing the embedded arbitrary URL payload (Meta Advisory, CyberSecurityNews, Rewterz).

Impact

Successful exploitation allows an attacker to trigger arbitrary URL processing on the victim's iOS or macOS device without any user interaction, effectively enabling remote content fetching and, when chained with CVE-2025-43300, delivery of sophisticated spyware to targeted Apple devices. The vulnerability was linked to government-grade spyware campaigns, including deployment of the commercial "Landfall" spyware on Samsung devices via a related exploit chain, and Apple subsequently issued spyware threat notifications to users in multiple countries including France. The confidentiality and integrity of targeted devices were compromised, with potential for full device surveillance, data exfiltration, and persistent access (CISA KEV, TechCrunch, Unit42).

Exploitation steps

  1. Reconnaissance: Identify a high-value target who uses WhatsApp for iOS or Mac (versions prior to the patched releases). The attacker requires only a valid WhatsApp account to initiate contact with the target.
  2. Craft malicious payload: Prepare a specially crafted DNG (Digital Negative) image file or linked device synchronization message embedding an attacker-controlled URL as the content payload.
  3. Deliver via WhatsApp: Send the malicious DNG image or crafted synchronization message to the target's WhatsApp account. No interaction from the victim is required — the message is processed automatically by the WhatsApp client upon receipt.
  4. Trigger URL processing: The incomplete authorization check in WhatsApp's linked device sync handler causes the target device to fetch and process content from the attacker-specified arbitrary URL without user awareness.
  5. Chain with OS-level exploit: Leverage CVE-2025-43300 (Apple OS-level vulnerability) to escalate from URL processing to code execution or spyware installation on the target device.
  6. Deploy spyware: Install commercial-grade spyware (e.g., Landfall) for persistent surveillance, data exfiltration, and remote access (Meta Advisory, CyberSecurityNews, Rewterz).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS connections from the WhatsApp process to unknown or suspicious external URLs immediately after receiving a message; connections to infrastructure associated with commercial spyware operators.
  • File System: Presence of unexpected DNG image files in WhatsApp's media cache or temporary directories; newly installed or modified system frameworks or daemons following WhatsApp message receipt; spyware artifacts consistent with Landfall or similar commercial tools.
  • Logs: WhatsApp application logs showing URL fetch requests triggered without explicit user action; iOS/macOS system logs recording process launches or network activity originating from the WhatsApp process at the time of message receipt.
  • Process Behavior: Unusual child processes spawned by WhatsApp (e.g., shell commands, network utilities); WhatsApp process making unexpected system calls or accessing sensitive device resources (contacts, camera, microphone) without user interaction.
  • Device Indicators: Apple threat notification received warning of mercenary spyware targeting; unexpected linked devices appearing in WhatsApp's linked devices list; device battery drain or unusual background data usage consistent with spyware activity (Meta Advisory, SecurityWeek, Unit42).

Mitigation and workarounds

Meta released patched versions addressing CVE-2025-55177: WhatsApp for iOS v2.25.21.73 or later, WhatsApp Business for iOS v2.25.21.78 or later, and WhatsApp for Mac v2.25.21.78 or later. Users should update immediately via the App Store or Mac App Store. CISA directed federal agencies to apply mitigations by September 23, 2025, per BOD 22-01. Additionally, Apple backported fixes for the companion OS-level vulnerability CVE-2025-43300 to older iOS and iPadOS versions — users should also ensure their Apple OS is fully updated. As a precautionary measure, users can review and remove any unrecognized linked devices in WhatsApp settings and enable Lockdown Mode on iOS for high-risk individuals (WhatsApp Advisory, CISA KEV, The Hacker News).

Community reactions

Meta issued an emergency security advisory and proactively notified affected users, describing the exploitation as a "sophisticated attack against specific targeted users" — language consistent with state-sponsored or commercial spyware operations. Security researchers and media widely covered the disclosure, with TechCrunch, SecurityWeek, Forbes, Gizmodo, and PCMag among outlets reporting on the zero-click nature and spyware context. CISA added the vulnerability to its KEV catalog within days of disclosure, signaling high urgency. Apple subsequently issued spyware threat notifications to users in France and other countries, and CERT-FR confirmed the campaign. The 39C3 (Chaos Communication Congress 2025) conference featured a deep-dive talk titled "DNGerousLINK: A Deep Dive into WhatsApp 0-Click Exploits on iOS and Samsung Devices," providing detailed technical analysis of the exploit chain. Community sentiment on social media (Mastodon, Bluesky, Reddit) was alarmed, with widespread calls to update WhatsApp immediately (Meta Advisory, TechCrunch, CCC Talk).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45568CRITICAL9.9
  • Python logoPython
  • zrok
NoYesJul 16, 2026
CVE-2026-45576HIGH8.3
  • NixOS logoNixOS
  • github.com/openziti/zrok
NoYesJul 16, 2026
CVE-2026-36590HIGH7.5
  • NixOS logoNixOS
  • nanomq
NoNoJul 15, 2026
CVE-2026-59259MEDIUM6
  • NixOS logoNixOS
  • n8n
NoYesJul 15, 2026
CVE-2026-26032MEDIUM5.4
  • NixOS logoNixOS
  • ivy
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management