VDB
CVE-2025-55177
CVE-2025-55177
PUBLISHED
KEV
CVSS 8 HIGH
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
EPSS 4.30% · 90.7th percentile
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
4.30%
90.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 2.22.25.2, 2.22.25.2 | ||
| WhatsApp Business for iOS | 2.22.25.2 | |
| whatsapp_business | 2.22.25.2 | |
| WhatsApp Desktop for Mac | 2.22.25.2 | |
| WhatsApp for iOS | 2.22.25.2 |
Timeline
- Aug 20, 2025 VulnCheck KEV Exploitation
- Aug 20, 2025 PoC Published
- Aug 29, 2025 VulnCheck KEV Exploitation
- Aug 29, 2025 CVE Published
- Aug 29, 2025 PoC Published
- Aug 29, 2025 PoC Published
- Aug 29, 2025 PoC Published
- Aug 29, 2025 PoC Published
- Aug 29, 2025 PoC Published
- Aug 29, 2025 PoC Published
- Aug 29, 2025 PoC Published
- Aug 30, 2025 EPSS Score
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55177 advisory
- https://www.facebook.com/security/advisories/cve-2025-55177 url
- https://www.whatsapp.com/security/advisories/2025/ url
- https://nvd.nist.gov/vuln/detail/CVE-2025-55177 advisory
- https://www.whatsapp.com/security/advisories/2025 url