CVE-2025-55177 Details
Description
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
A vulnerability exists in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78, due to incomplete authorization of linked device synchronization messages. This vulnerability could have allowed an unrelated user to initiate the processing of content from an arbitrary URL on a target device. It is believed that this issue, combined with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against certain targeted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55177 | CISA-ADP | US Government Resource |
| https://www.facebook.com/security/advisories/cve-2025-55177 | [email protected] | Vendor Advisory |
| https://www.whatsapp.com/security/advisories/2025/ | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Meta Platforms WhatsApp Incorrect Authorization Vulnerability | Sep 2, 2025 | Sep 23, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| whatsapp whatsapp | >= 2.22.25.2, < 2.25.21.73 >= 2.22.25.2, < 2.25.21.78 |
CPE
Remediation
| |
| whatsapp whatsapp business | >= 2.22.25.2, < 2.25.21.78 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Sep 3, 2025 | Initial Analysis | [email protected] |
| Sep 3, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Sep 2, 2025 | CVE Modified | CISA-ADP |
| Aug 30, 2025 | CVE Modified | [email protected] |
| Aug 29, 2025 | CVE Modified | CISA-ADP |
| Aug 29, 2025 | New CVE Received | [email protected] |