CVE-2025-30259 Details
Description
The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.
A vulnerability in the WhatsApp cloud service, present prior to late 2024, allowed certain crafted PDF files to bypass sandbox protections. This flaw enabled remote access to messaging applications by third parties. The vulnerability was exploited in 2024 to deploy Android malware linked to Paragon Solutions, targeting journalists and activists in Italy.
WhatsApp has patched this vulnerability, removing the exploit vector without requiring a client-side fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 20, 2025CISA-ADP
Assessed Mar 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/ | [email protected] | BundleTechnical Analysis |
| https://www.bleepingcomputer.com/news/security/whatsapp-patched-zero-day-flaw-used-in-paragon-spyware-attacks/ | [email protected] | Media CoverageRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
All versions | |
CPE
Remediation
| |
| Paragon Graphite | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | New CVE Received | [email protected] |
Volerion