CVE-2025-55177

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:macos:*:*
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*

History

03 Sep 2025, 14:03

Type Values Removed Values Added
First Time Whatsapp
Whatsapp whatsapp Business
Whatsapp whatsapp
References () https://www.facebook.com/security/advisories/cve-2025-55177 - () https://www.facebook.com/security/advisories/cve-2025-55177 - Vendor Advisory
References () https://www.whatsapp.com/security/advisories/2025/ - () https://www.whatsapp.com/security/advisories/2025/ - Vendor Advisory
CPE cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:macos:*:*
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*
CWE CWE-863

30 Aug 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.facebook.com/security/advisories/cve-2025-55177 -
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 5.4

29 Aug 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

29 Aug 2025, 16:24

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-29 16:15

Updated : 2025-09-03 14:03


NVD link : CVE-2025-55177

Mitre link : CVE-2025-55177

CVE.ORG link : CVE-2025-55177


JSON object : View

Products Affected

whatsapp

  • whatsapp_business
  • whatsapp
CWE
CWE-863

Incorrect Authorization