Vulnerability record · CVE-2025-55177 · published 29 August 2025
CVE-2025-55177: WhatsApp iOS and Mac linked-device sync authorization flaw
Whatsapp · Whatsapp
WhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated user cause the target device to process content from an arbitrary URL. The vendor states this flaw, chained with an Apple OS-level vulnerability (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Description
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Automated analysis
high priorityConfirmed exploitation in targeted attacks per CISA KEV and the vendor, though the standalone CVSS impact is limited and the full effect depends on chaining with an OS-level flaw.
What it is
WhatsApp for iOS, WhatsApp Business for iOS and WhatsApp for Mac fail to fully authorize linked-device synchronization messages, letting an unrelated user cause the target device to process content from an arbitrary URL. The vendor states this flaw, chained with an Apple OS-level vulnerability (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Impact
An attacker can force a victim's device to fetch and process content from an attacker-chosen URL without the victim's involvement, which in the reported chain served as a step toward a more serious compromise. On its own the flaw yields limited confidentiality and integrity impact, not code execution.
Attack surface
Reached over the network through WhatsApp's linked-device synchronization path; the vector requires low privileges (PR:L) and no user interaction (UI:N), meaning the attacker needs a WhatsApp account and a linked-device relationship rather than the victim's action. No authentication as the victim is required.
Exploitation
Listed in CISA KEV (added 2025-09-02, due 2025-09-23) with vendor and CISA references indicating exploitation in targeted attacks; EPSS 30-day probability is 0.042 (90th percentile). No ransomware campaign use is documented.
What to do
- Update WhatsApp for iOS to v2.25.21.73 or later, and WhatsApp Business for iOS and WhatsApp for Mac to v2.25.21.78 or later.
- Apply current Apple iOS and macOS security updates to close the chained OS-level vulnerability CVE-2025-43300.
- Review and unlink unknown or unused linked devices from WhatsApp accounts, and restrict who can link devices.
- Treat WhatsApp on unpatched Apple devices as high risk for targeted users and follow CISA BOD 22-01 remediation timelines.
- Monitor vendor advisories for updated fixed versions if the listed builds are superseded.
Detection
- Audit WhatsApp linked-device lists for unexpected or unrecognized devices on high-value accounts.
- Monitor network egress from WhatsApp clients for requests to unusual or newly registered domains.
- Correlate endpoint telemetry for WhatsApp processes spawning or triggering URL handling on iOS and macOS.
- Track patch state of WhatsApp and Apple OS versions across managed mobile and Mac fleets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-55177 to the Known Exploited Vulnerabilities catalog on 2 September 2025 as "Meta Platforms WhatsApp Incorrect Authorization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 September 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.facebook.com/security/advisories/cve-2025-55177 | Vendor Advisory |
| https://www.whatsapp.com/security/advisories/2025/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55177 | US Government Resource |
Track CVE-2025-55177 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-55177), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.