CVE-2025-55177: Meta Platforms WhatsApp Incorrect Authorization Vulnerability
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55177?
CVE-2025-55177 is classified as a high-severity vulnerability due to the potential for unauthorized access to user data.
How do I fix CVE-2025-55177?
To fix CVE-2025-55177, update WhatsApp for iOS to version 2.25.21.73 or later, WhatsApp Business for iOS to version 2.25.21.78 or later, and WhatsApp for Mac to version 2.25.21.78 or later.
What specific devices are affected by CVE-2025-55177?
CVE-2025-55177 affects WhatsApp on iOS versions prior to 2.25.21.73, WhatsApp Business on iOS prior to 2.25.21.78, and WhatsApp for Mac prior to version 2.25.21.78.
What type of attack can CVE-2025-55177 facilitate?
CVE-2025-55177 can facilitate unauthorized users triggering the processing of content from arbitrary URLs on a target's device.
Is there a risk of data exposure with CVE-2025-55177?
Yes, CVE-2025-55177 presents a risk of data exposure as it allows unauthorized access to potentially sensitive user data.