CVE-2025-55179
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-55179 is a vulnerability caused by incomplete validation of rich response messages in WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac. It could allow an authenticated user to trigger processing of media content from an arbitrary URL on another user's device without that user's interaction. Affected versions include WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS prior to v2.25.23.82, and WhatsApp for Mac prior to v2.25.23.83. It was published on November 18, 2025, and carries a CVSS v3.1 base score of 5.4 (Medium) (WhatsApp Advisory, Meta Advisory).

Technical details

The root cause is incomplete input validation when processing rich response messages (CWE-863: Incorrect Authorization), allowing an attacker to craft a message that causes the recipient's WhatsApp client to fetch and process media content from an attacker-controlled or arbitrary URL. The attack vector is network-based, requires low privileges (an authenticated WhatsApp account), and no user interaction on the victim's side. Affected version ranges begin at 2.25.8.14 (Mac/Business iOS) and 2.25.8.17 (iOS) respectively (Meta Advisory, WhatsApp Advisory).

Impact

Successful exploitation could allow an attacker to cause the victim's device to make outbound requests to arbitrary URLs, potentially exposing limited confidential data (e.g., IP address, device metadata) and enabling minor content manipulation, reflected in the CVSS low confidentiality and integrity impact ratings. There is no availability impact. The vulnerability does not require victim interaction, increasing the risk of silent data exposure across all users of affected iOS and Mac WhatsApp clients (Meta Advisory, WhatsApp Advisory).

Exploitability

Meta has stated there is no evidence of exploitation in the wild, and no public proof-of-concept exploit is known (Meta Advisory). The EPSS score is approximately 0.025% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a target WhatsApp user on iOS or Mac running a vulnerable version (WhatsApp for iOS < 2.25.23.73, WhatsApp Business for iOS < 2.25.23.82, or WhatsApp for Mac < 2.25.23.83).
  2. Craft malicious rich response message: As an authenticated WhatsApp user, construct a specially crafted rich response message that embeds an arbitrary attacker-controlled media URL, exploiting the incomplete validation logic.
  3. Send message to target: Deliver the crafted message to the victim's WhatsApp account via any available chat channel (direct message or group).
  4. Trigger media processing: The victim's vulnerable WhatsApp client automatically processes the rich response message and fetches media content from the attacker-specified URL without requiring any user interaction.
  5. Collect data: The outbound request from the victim's device to the attacker's server may reveal the victim's IP address, device metadata, or other request headers, and could potentially be used to serve malicious content (Meta Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from a user's iOS or Mac device to unfamiliar or attacker-controlled URLs, initiated by the WhatsApp process without explicit user action.
  • Logs: Network traffic logs showing WhatsApp client fetching media from domains not associated with Meta/WhatsApp CDN infrastructure (e.g., *.whatsapp.net, *.fbcdn.net).
  • Process: WhatsApp application making URL fetch requests to arbitrary external hosts in the background, observable via network monitoring tools on managed devices.

Mitigation and workarounds

Meta has released patched versions addressing this vulnerability: WhatsApp for iOS v2.25.23.73 or later, WhatsApp Business for iOS v2.25.23.82 or later, and WhatsApp for Mac v2.25.23.83 or later. Users should update their WhatsApp applications immediately via the App Store or Mac App Store and enable automatic updates to ensure timely patching of future vulnerabilities. No configuration-based workaround is available; updating to the fixed version is the only remediation (WhatsApp Advisory, Meta Advisory).

Community reactions

The vulnerability received limited but notable attention in the security community upon disclosure in November 2025. Discussion was observed on Mastodon/infosec.exchange and aggregated by vulnerability tracking platforms such as VulDB and CIRCL. Coverage by CyberInsider noted the broader context of WhatsApp data exposure risks. Red Hat also tracked the CVE for informational purposes, though their products are not directly affected (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84121CRITICAL9.6
  • NixOS logoNixOS
  • firefox-esr
NoYesSep 01, 2026
CVE-2026-84123HIGH8.8
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84125MEDIUM5.4
  • NixOS logoNixOS
  • firefox
NoYesSep 01, 2026
CVE-2026-84124MEDIUM5.4
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026
CVE-2026-84122MEDIUM5.4
  • NixOS logoNixOS
  • firefox-esr
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management