Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-55177 Details

Description

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Meta Platforms WhatsApp Incorrect Authorization VulnerabilitySep 2, 2025Sep 23, 2025Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-863Incorrect Authorization[email protected]

Affected Products

ProductVersions
whatsapp whatsapp
>= 2.22.25.2, < 2.25.21.73
>= 2.22.25.2, < 2.25.21.78

CPE

  • cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
  • cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:macos:*:*

Remediation

  • No remediation found in references.
whatsapp whatsapp business
>= 2.22.25.2, < 2.25.21.78

CPE

  • cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-55177
NVD Published Date:
Aug 29, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-55177 Details - Not Deferred