
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55179 is a vulnerability caused by incomplete validation of rich response messages in WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac. It could allow an authenticated user to trigger processing of media content from an arbitrary URL on another user's device without that user's interaction. Affected versions include WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS prior to v2.25.23.82, and WhatsApp for Mac prior to v2.25.23.83. It was published on November 18, 2025, and carries a CVSS v3.1 base score of 5.4 (Medium) (WhatsApp Advisory, Meta Advisory).
The root cause is incomplete input validation when processing rich response messages (CWE-863: Incorrect Authorization), allowing an attacker to craft a message that causes the recipient's WhatsApp client to fetch and process media content from an attacker-controlled or arbitrary URL. The attack vector is network-based, requires low privileges (an authenticated WhatsApp account), and no user interaction on the victim's side. Affected version ranges begin at 2.25.8.14 (Mac/Business iOS) and 2.25.8.17 (iOS) respectively (Meta Advisory, WhatsApp Advisory).
Successful exploitation could allow an attacker to cause the victim's device to make outbound requests to arbitrary URLs, potentially exposing limited confidential data (e.g., IP address, device metadata) and enabling minor content manipulation, reflected in the CVSS low confidentiality and integrity impact ratings. There is no availability impact. The vulnerability does not require victim interaction, increasing the risk of silent data exposure across all users of affected iOS and Mac WhatsApp clients (Meta Advisory, WhatsApp Advisory).
Meta has stated there is no evidence of exploitation in the wild, and no public proof-of-concept exploit is known (Meta Advisory). The EPSS score is approximately 0.025% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
*.whatsapp.net, *.fbcdn.net).Meta has released patched versions addressing this vulnerability: WhatsApp for iOS v2.25.23.73 or later, WhatsApp Business for iOS v2.25.23.82 or later, and WhatsApp for Mac v2.25.23.83 or later. Users should update their WhatsApp applications immediately via the App Store or Mac App Store and enable automatic updates to ensure timely patching of future vulnerabilities. No configuration-based workaround is available; updating to the fixed version is the only remediation (WhatsApp Advisory, Meta Advisory).
The vulnerability received limited but notable attention in the security community upon disclosure in November 2025. Discussion was observed on Mastodon/infosec.exchange and aggregated by vulnerability tracking platforms such as VulDB and CIRCL. Coverage by CyberInsider noted the broader context of WhatsApp data exposure risks. Red Hat also tracked the CVE for informational purposes, though their products are not directly affected (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."