
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55177 is an incorrect authorization vulnerability in WhatsApp's linked device synchronization mechanism that enables zero-click exploitation on Apple platforms. An unrelated, authenticated user can trigger processing of content from an arbitrary URL on a target's device without any interaction from the victim. Affected versions include WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS prior to v2.25.21.78, and WhatsApp for Mac prior to v2.25.21.78 (versions from 2.22.25.2 onward). Meta disclosed the vulnerability on August 29, 2025, and assessed that it was exploited in combination with an Apple OS-level vulnerability (CVE-2025-43300) in sophisticated attacks against specific targeted users. The CVSS v3.1 base score is 5.4 (Medium) (Meta Advisory, CISA KEV).
The root cause is classified as CWE-863 (Incorrect Authorization): WhatsApp's linked device synchronization messages were not fully authorized, allowing an unrelated user — one who is not a legitimate linked device owner — to send specially crafted synchronization messages that cause the target's device to fetch and process content from an attacker-controlled URL. The attack vector is network-based, requires low privileges (a valid WhatsApp account), and requires no user interaction, making it a true zero-click vulnerability. Exploitation was chained with CVE-2025-43300, an OS-level Apple vulnerability, to achieve more impactful outcomes such as spyware delivery. Later research revealed that malicious DNG (Digital Negative) image files sent via WhatsApp were used as the delivery mechanism to trigger the flaw, with the image parser processing the embedded arbitrary URL payload (Meta Advisory, CyberSecurityNews, Rewterz).
Successful exploitation allows an attacker to trigger arbitrary URL processing on the victim's iOS or macOS device without any user interaction, effectively enabling remote content fetching and, when chained with CVE-2025-43300, delivery of sophisticated spyware to targeted Apple devices. The vulnerability was linked to government-grade spyware campaigns, including deployment of the commercial "Landfall" spyware on Samsung devices via a related exploit chain, and Apple subsequently issued spyware threat notifications to users in multiple countries including France. The confidentiality and integrity of targeted devices were compromised, with potential for full device surveillance, data exfiltration, and persistent access (CISA KEV, TechCrunch, Unit42).
Meta released patched versions addressing CVE-2025-55177: WhatsApp for iOS v2.25.21.73 or later, WhatsApp Business for iOS v2.25.21.78 or later, and WhatsApp for Mac v2.25.21.78 or later. Users should update immediately via the App Store or Mac App Store. CISA directed federal agencies to apply mitigations by September 23, 2025, per BOD 22-01. Additionally, Apple backported fixes for the companion OS-level vulnerability CVE-2025-43300 to older iOS and iPadOS versions — users should also ensure their Apple OS is fully updated. As a precautionary measure, users can review and remove any unrecognized linked devices in WhatsApp settings and enable Lockdown Mode on iOS for high-risk individuals (WhatsApp Advisory, CISA KEV, The Hacker News).
Meta issued an emergency security advisory and proactively notified affected users, describing the exploitation as a "sophisticated attack against specific targeted users" — language consistent with state-sponsored or commercial spyware operations. Security researchers and media widely covered the disclosure, with TechCrunch, SecurityWeek, Forbes, Gizmodo, and PCMag among outlets reporting on the zero-click nature and spyware context. CISA added the vulnerability to its KEV catalog within days of disclosure, signaling high urgency. Apple subsequently issued spyware threat notifications to users in France and other countries, and CERT-FR confirmed the campaign. The 39C3 (Chaos Communication Congress 2025) conference featured a deep-dive talk titled "DNGerousLINK: A Deep Dive into WhatsApp 0-Click Exploits on iOS and Samsung Devices," providing detailed technical analysis of the exploit chain. Community sentiment on social media (Mastodon, Bluesky, Reddit) was alarmed, with widespread calls to update WhatsApp immediately (Meta Advisory, TechCrunch, CCC Talk).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."