← Vulnerability feed

Vulnerability record · CVE-2025-55177 · published 29 August 2025

CVE-2025-55177: WhatsApp iOS and Mac linked-device sync authorization flaw

Whatsapp · Whatsapp

WhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated user cause the target device to process content from an arbitrary URL. The vendor states this flaw, chained with an Apple OS-level vulnerability (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

5.4 CVSS 3.1 Medium CISA KEV since 2 Sep 2025 EPSS 4.3% · top 9.2% CWE-863 · Incorrect authorization
5.4CVSS 3.1 base score
4.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityConfirmed exploitation in targeted attacks per CISA KEV and the vendor, though the standalone CVSS impact is limited and the full effect depends on chaining with an OS-level flaw.

What it is

WhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated user cause the target device to process content from an arbitrary URL. The vendor states this flaw, chained with an Apple OS-level vulnerability (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

Impact

An attacker can force a victim's device to fetch and process content from an attacker-chosen URL without the victim's involvement, which in the reported chain served as a step toward a more serious compromise. On its own the flaw yields limited confidentiality and integrity impact, not code execution.

Attack surface

Reached over the network through WhatsApp's linked-device synchronization path; the vector requires low privileges (PR:L) and no user interaction (UI:N), meaning the attacker needs a WhatsApp account and a linked-device relationship rather than the victim's action. No authentication as the victim is required.

Exploitation

Listed in CISA KEV (added 2025-09-02, due 2025-09-23) with vendor and CISA references indicating exploitation in targeted attacks; EPSS 30-day probability is 0.042 (90th percentile). No ransomware campaign use is documented.

What to do

  • Update WhatsApp for iOS to v2.25.21.73 or later, and WhatsApp Business for iOS and WhatsApp for Mac to v2.25.21.78 or later.
  • Apply current Apple iOS and macOS security updates to close the chained OS-level vulnerability CVE-2025-43300.
  • Review and unlink unknown or unused linked devices from WhatsApp accounts, and restrict who can link devices.
  • Treat WhatsApp on unpatched Apple devices as high risk for targeted users and follow CISA BOD 22-01 remediation timelines.
  • Monitor vendor advisories for updated fixed versions if the listed builds are superseded.

Detection

  • Audit WhatsApp linked-device lists for unexpected or unrecognized devices on high-value accounts.
  • Monitor network egress from WhatsApp clients for requests to unusual or newly registered domains.
  • Correlate endpoint telemetry for WhatsApp processes spawning or triggering URL handling on iOS and macOS.
  • Track patch state of WhatsApp and Apple OS versions across managed mobile and Mac fleets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-55177 to the Known Exploited Vulnerabilities catalog on 2 September 2025 as "Meta Platforms WhatsApp Incorrect Authorization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 September 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55177 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3568WhatsApp VOIP stack heap buffer overflow allows remote code executionA heap-based buffer overflow in the WhatsApp VOIP stack can be triggered by a specially crafted series of RTCP packets sent to a target phone number,…KEVEPSS 30%analysed8.2CVE-2019-18426WhatsApp Desktop link preview XSS and local file readWhatsApp Desktop before 0.3.9309, when paired with WhatsApp for iPhone before 2.20.10, is vulnerable to cross-site scripting and local file reading. …KEVEPSS 68%analysed9.8CVE-2022-36934Whatsapp heap-based buffer overflow vulnerabilityAn integer overflow in WhatsApp could result in remote code execution in an established video call.EPSS 2.4%9.8CVE-2021-24042Whatsapp heap-based buffer overflow vulnerabilityThe calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, W…EPSS 1.2%9.8CVE-2021-24041Whatsapp heap-based buffer overflow vulnerabilityA missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowe…EPSS 1.4%9.8CVE-2021-24026Whatsapp out-of-bounds write vulnerabilityA missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android …EPSS 1.4%9.8CVE-2020-1909Whatsapp use after free vulnerabilityA use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in …EPSS 2.3%9.8CVE-2020-1907Whatsapp out-of-bounds write vulnerabilityA stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2025-55177), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.