VDB

CVE-2025-55177

CVE-2025-55177 PUBLISHED KEV CVSS 8 HIGH

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

EPSS 4.30% · 90.7th percentile

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
4.30%
90.7th percentile

Affected Products

VendorProductVersions
whatsappwhatsapp2.22.25.2, 2.22.25.2
FacebookWhatsApp Business for iOS2.22.25.2
whatsappwhatsapp_business2.22.25.2
FacebookWhatsApp Desktop for Mac2.22.25.2
FacebookWhatsApp for iOS2.22.25.2

Timeline

  • Aug 20, 2025 VulnCheck KEV Exploitation
  • Aug 20, 2025 PoC Published
  • Aug 29, 2025 VulnCheck KEV Exploitation
  • Aug 29, 2025 CVE Published
  • Aug 29, 2025 PoC Published
  • Aug 29, 2025 PoC Published
  • Aug 29, 2025 PoC Published
  • Aug 29, 2025 PoC Published
  • Aug 29, 2025 PoC Published
  • Aug 29, 2025 PoC Published
  • Aug 29, 2025 PoC Published
  • Aug 30, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›