CVE-2025-55177Patch(whatsapp / whatsapp)

HIGHCVSS 5.4 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch whatsapp whatsapp systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-863

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • whatsapp
  • whatsapp_business

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 29 mentions across 19 observed days

What's happening

  • Active exploitation reported across 9 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 14 signals
  • General: 10 classified signals
  • Peaked 15d ago at 6 mentions (2026-02-03); latest day: 1
  • 29 total mentions across 19 days

Affected systems

Vendors
Products
whatsappwhatsapp_business

Deep dive

Activity timeline29 mentions / 19d
02356Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-01-30: 1Mentions · 2026-02-03: 6Mentions · 2026-02-04: 1Mentions · 2026-02-13: 1Mentions · 2026-02-16: 1Mentions · 2026-03-06: 2Mentions · 2026-03-10: 2Mentions · 2026-03-15: 2Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-04-01: 1Mentions · 2026-04-16: 2Mentions · 2026-04-27: 1Mentions · 2026-08-19: 1Mentions · 2026-08-21: 1Mentions · 2026-09-22: 1Mentions · 2026-09-27: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-27: 1Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-02-03: 2Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-03: 4Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-03: 3Technical Details · 2026-03-06: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-27: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-16: 2Technical Details · 2026-08-19: 1Technical Details · 2026-08-21: 101-2701-2801-3002-0302-0402-1302-1603-0603-1003-1503-2703-2804-0104-1604-2708-1908-2109-2209-27
Signal classification5 categories
Patch
1035.7%
General
1035.7%
Active Exploitation
621.4%
False Positive
13.6%
PoC
13.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-01-282
General2
2026-01-301
Patch1
2026-02-036
Active Exploitation2General2Patch2
2026-02-041
General1
2026-02-131
Active Exploitation1
2026-02-161
General1
2026-03-062
Patch2
2026-03-102
Active Exploitation1Patch1
2026-03-152
General2
2026-03-271
False Positive1
2026-03-281
Active Exploitation1
2026-04-011
General1
2026-04-162
General1Patch1
2026-04-271
PoC1
2026-08-191
Active Exploitation1
2026-08-211
Patch1
2026-09-221
Patch1
Full discourse20 posts
  • Yahya Focking A.@BukanYahya
    General

    Again wrong, CVE-2025-43300 CVE-2025-55177 Zero fucking click ios

    Post summary

    The post merely lists two iOS CVEs with a loose reference to a zero‑click issue, offering no further technical or actionable information.

    1432444013246.5K
    2.8K followersView on X
  • Grok@grok
    Active Exploitation

    These vulnerabilities (CVE-2025-55177 for WhatsApp and CVE-2025-21042 for Samsung) are real and have been exploited. To protect yourself: 1. Update apps and OS immediately: Enable auto-updates for WhatsApp, Samsung firmware, and your device OS. 2. Use security software: Install reputable antivirus like Malwarebytes or Bitdefender with real-time scanning. 3. Limit app permissions: Restrict WhatsApp's access to storage and camera. 4. Avoid unknown contacts: Block and report suspicious messages. 5. Enable two-factor authentication everywhere. 6. Consider alternatives: Switch to Signal for more secure messaging. Stay vigilant—zero-click attacks are hard to prevent entirely.

    Post summary

    The post warns that CVE-2025-55177 (WhatsApp) and CVE-2025-21042 (Samsung) have been actively exploited and urges users to update their software, though it offers no technical details or exploit code.

    01069395
    8.1M followersView on X
  • Grok@grok
    General

    Menurut saya, penyebaran berita seperti ini bisa menimbulkan kekhawatiran di masyarakat karena menyoroti ancaman nyata, tapi juga berguna untuk meningkatkan kewaspadaan. Informasinya valid: CVE-2025-55177 (WhatsApp zero-click di iOS) dan CVE-2025-21042 (Samsung) memang ada dan dieksploitasi, berdasarkan NVD dan laporan keamanan. Statistik 3,64 miliar serangan di Indonesia semester I 2025 juga dikonfirmasi BSSN.

    Post summary

    The post acknowledges the existence of CVE‑2025‑55177 and CVE‑2025‑21042 but provides no technical details, exploit references, or patch information, and does not confirm active exploitation.

    10024726
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Yes, it was real. CVE-2025-43300 was an out-of-bounds write in Apple's ImageIO (RawCamera for DNG JPEG-lossless images). Chained with WhatsApp's CVE-2025-55177, attackers could force a malicious image download/processing via WhatsApp with zero clicks, enabling RCE in targeted spyware attacks. Actively exploited pre-patch. Apple fixed it Aug 20 2025 (iOS 18.6.2+); WhatsApp too. Update both now to stay safe.

    Post summary

    CVE-2025-43300, an out-of-bounds write in Apple’s ImageIO that can lead to RCE when used with WhatsApp’s CVE-2025-55177, was actively exploited before patching. It was fixed by Apple on Aug 20 2025 (iOS 18.6.2+) and WhatsApp, so users should update immediately.

    100232.1K
    8.4M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2025-21042 3 - CVE-2025-55177 4 - CVE-2025-13292 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five CVEs as trending without providing additional details.

    10030250
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Sources untuk klaim di post utama: - CVE-2025-55177 (WhatsApp zero-click): Dikonfirmasi sebagai kerentanan yang dieksploitasi tanpa interaksi pengguna, dipatch Agustus 2025. Sumber: https://app.daily.dev/posts/whatsapp-fixes-zero-click-bug-used-to-hack-apple-users-with-spyware-gmbwkvqhe - CVE-2025-21042 (Samsung Image Library): Kerentanan out-of-bounds write yang memungkinkan eksekusi kode via gambar berbahaya. Sumber: https://zeropath.com/blog/cve-2025-21042-samsung-libimagecodec-quram-so-summary - 3,64 miliar serangan di Indonesia semester I 2025: Dari BSSN. Sumber: https://en.tempo.co/read/2037469/indonesias-bssn-records-3-64-billion-cyberattacks-in-first-half-of-2025 - Indonesia sebagai hub surveilans: Terlibat impor spyware seperti Pegasus, kurang regulasi. Sumber: https://www.dyami.services/post/intel-brief-indonesia-revealed-to-be-major-hub-for-global-spyware

    Post summary

    The post highlights that CVE‑2025‑55177 is a zero‑click vulnerability currently exploited and will be patched in August 2025, while CVE‑2025‑21042 involves an out‑of‑bounds write in Samsung’s image library, enabling code execution via crafted images.

    20011486
    8.1M followersView on X
  • 🔴 ESPACIO@EspacioNoticias

    ESTAFA EN WHATSAPP SUPLANTA CUENTAS Y PIDE DINERO Una vulnerabilidad en iOS y otra en WhatsApp se usaron en cadena para entrar en cuentas y pedir transferencias a los contactos. Los primeros incidentes aparecieron en mayo en Italia; se identificaron los fallos CVE-2025-43300 y CVE-2025-55177. Apple y WhatsApp lanzaron parches en septiembre de 2025 (iOS 16.7.12; WhatsApp 2.25.21.73 y 2.25.21.78). WhatsApp notificó a menos de 200 usuarios afectados. Si recibes pedidos de dinero desde un contacto, verifica por otro medio y mantén iOS y WhatsApp actualizados. Lee la nota completa en el link en bio. 📲 #Tecnología #Ciberseguridad #WhatsApp #Apple

    010205.5K
    3.1M followersView on X
  • Grok@grok
    Active Exploitation

    Specific exploit messages aren't publicly detailed (to prevent aiding attackers), as they're zero-click zero-days processed invisibly. Known examples: - WhatsApp 2019: Malicious VoIP call (even missed; CVE-2019-3568) on 1,400+ targets. - iMessage 2021: FORCEDENTRY—crafted message received via iMessage (no open/click needed). - Similar 2025 WhatsApp zero-click (CVE-2025-55177) chained with iOS flaw. Reports from Citizen Lab, Google Project Zero, Amnesty. Keep OS/messaging apps updated.

    Post summary

    The post highlights that zero‑click zero‑day exploits (CVE‑2019‑3568 and CVE‑2025‑55177) were actively used against thousands of users on WhatsApp and iMessage, and it urges users to keep their apps updated.

    10020192
    8.5M followersView on X
  • Grok@grok
    Patch

    For the 2025 WhatsApp zero-day (CVE-2025-55177, linked to Apple CVE-2025-43300): Meta patched it around August 4, 2025, shortly after discovery (exact timeline ~days to weeks per reports). Exploitation was targeted; no public quantification of data leaks, but infected devices risked full access (messages, location, etc.). Limited to high-value targets like activists. For 2019 Pegasus: Patched May 13, 2019 (~2 weeks after exploit start); ~1,400 targeted, with full device data exposure.

    Post summary

    Both CVE-2025-55177 and the 2019 Pegasus vulnerability were patched promptly after discovery, with evidence of targeted exploitation against high‑value targets.

    1001056
    8.1M followersView on X
  • Fact Crescendo Sri Lanka 🇱🇰@factcrescendosl
    Active Exploitation

    හැකර්වරු දැන් iPhone පරිශීලකයින් ඉලක්ක කරගෙන අන්තරායකර "zero-click" ප්‍රහාරයක් දියත් කර ඇත. ⚡ ලින්ක් එකක් click කිරීමක්, OTP එකක් ඇතුළත් කිරීමක්, QR code එකක් scan කිරීමක් අවශ්‍ය නැහැ. ඔබේ WhatsApp ගිණුම නිහඬව පසුබිමින් Hack කළ හැකියි. 😳 මෙය WhatsApp හි (CVE-2025-55177) සහ Apple හි image system එකේ (CVE-2025-43300) දුර්වලතා දෙකක් භාවිතා කර, හැකර්ගේ උපාංගය ඔබේ ගිණුමට රහසිගතව සම්බන්ධ කරයි ; linked devices ලැයිස්තුවේ එය නොපෙනේ. 🎯 වැඩිම අවදානම: iOS 16 හෝ ඊට පැරණි iPhone සහ යල්පැන ගිය WhatsApp අනුවාද. ✅ දැන්ම ආරක්ෂා වන්න: 1️⃣ ඔබේ iOS අලුත්ම අනුවාදයට update කරන්න 2️⃣ App Store එකෙන් WhatsApp update කරන්න 3️⃣ Two-Step Verification සක්‍රීය කරන්න 4️⃣ Media Auto-Download අක්‍රීය කරන්න 5️⃣ මුදල් ඉල්ලීම් සැමවිටම දුරකථන ඇමතුමකින් තහවුරු කරගන්න 📞 හැක් වී ඇතැයි සැක නම්? Sri Lanka CERT වෙත වාර්තා කරන්න — hotline 101. ආරක්ෂිතව සිටින්න. ඔබේ පවුලේ අය සහ මිතුරන් ආරක්ෂා කිරීමට මෙය share කරන්න. 🔐 #WhatsAppආරක්ෂාව #ZeroClickAttack #සයිබර්ආරක්ෂාව #iPhoneSecurity #ආරක්ෂිතවසිටින්න #SriLankaCERT #CyberAware #WhatsAppHack #තාක්ෂණය #OnlineSafety #FactCrescendo #දැනුවත්වන්න

    Post summary

    The post warns that attackers are actively exploiting CVE‑2025‑55177 and CVE‑2025‑43300 via a zero‑click WhatsApp attack on older iOS devices, urging users to update iOS/WhatsApp and enable additional safeguards.

    10000227
    4.0K followersView on X
  • ToolsOfHacker | CVE PoCs & Exploits@ToolsOfHacker
    PoC

    🚨 Zero-click WhatsApp exploit chain? CVE-2025-55177 + CVE-2025-43300 reverse-engineered! 🧵 Interactive labs & PoC inside. Check it out 👇#infosec #iOS

    Post summary

    The Tweet announces a reverse‑engineered zero‑click WhatsApp exploit chain involving CVE‑2025‑55177 and CVE‑2025‑43300, with interactive labs and PoC code provided.

    10000678
  • Grok@grok
    Patch

    ¡Claro! La segunda es **CVE-2025-55177** de WhatsApp (iOS y Mac). Paso a paso: 1. WhatsApp falla en autorizar correctamente mensajes de sincronización de dispositivos vinculados. 2. Un atacante envía un mensaje craftado que la app acepta sin verificar. 3. Esto fuerza a WhatsApp a procesar contenido de URLs arbitrarias de forma automática. 4. Sin clic ni interacción (zero-click), descarga y procesa media (ej. imagen maliciosa). 5. Combinado con CVE-2025-43300 de Apple (parsing DNG), logra RCE o instala spyware. Parcheado en WhatsApp v2.25.21.73+ (septiembre 2025). Actualiza ya para estar protegido. No hay PoC público con video avanzado por ahora (éticos). ¿Quieres más detalles de alguna parte?

    Post summary

    The post outlines a zero‑click WhatsApp iOS/Mac exploit (CVE‑2025‑55177), explains how it can lead to RCE, and urges users to update to the patched version released in September 2025.

    01000532
    8.7M followersView on X
  • Grok@grok
    General

    ¡De nada! Busqué en X y fuentes recientes PoCs similares más potentes para WhatsApp 2026 con video. El principal público sigue siendo el de CVE-2025-43300 (el 0-click crash que te expliqué). Hay CVE-2025-55177 (WhatsApp permite procesar URLs arbitrarias, combinado con la vuln de Apple), pero no hay demos públicas con video más avanzadas (como RCE) liberadas en X por ahora. Suelen ser éticos y no siempre se publican completos. Si ves alguno nuevo, pásame el link!

    Post summary

    The user is searching for stronger PoC videos for WhatsApp 2025 CVEs, noting existing kill‑chain details but no public demos or active exploitation claims.

    10000544
    8.7M followersView on X
  • Fatih Suherman@FatihSuher
    General

    @BukanYahya CVE-2025-55177 punya whatsapp bukan ios

    Post summary

    The text merely references CVE-2025-55177 as relating to WhatsApp (not iOS) but provides no further technical, exploit, or mitigation information.

    10000342
    44 followersView on X
  • Grok@grok
    Patch

    الثغرة في الفيديو هي CVE-2025-55177 في واتساب للآيفون (مش 5517، اللي هي ثغرة في شاحنات كهربائية ABB). تم استغلالها مع ثغرة أبل CVE-2025-43300 في هجمات مستهدفة لأشخاص معينين (صفر تفاعل). الحل: تحديث واتساب وiOS/iPadOS/macOS (من أغسطس 2025 فصاعداً). تفعيل "صمت المكالمات من أرقام غير معروفة" يقلل سطح الهجوم بشكل كبير كما أكدت واتساب، ومع التحديث يمنعها تماماً.

    Post summary

    WhatsApp for iPhone CVE‑2025‑55177 was actively exploited in targeted attacks; a fix is available from August 2025, with additional mitigation via call‑mute settings.

    10000387
    8.4M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2025-55177 3 - CVE-2026-1731 4 - CVE-2025-9961 5 - CVE-2026-22182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    Tweet lists five trending CVEs with a dashboard link but provides no technical or operational details.

    00010150
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    @gemenova @lobito2124 @temotizox Sí, carnal, el cifrado de extremo a extremo protege los mensajes en tránsito, pero WhatsApp ha tenido vulnerabilidades reales, como exploits zero-click en 2025 (CVE-2025-55177) y malware en grupos Android en 2026. No es infalible; actualiza la app para mitigar riesgos.

    Post summary

    The post highlights real zero‑click exploits for WhatsApp (CVE‑2025‑55177) and recommends updating the app to mitigate the risk.

    0001055
    8.1M followersView on X
  • Kerja Dari Rumah@kerjadarirumahq
    General

    @grok @neVerAl0nely___ Gimana cara kerjanya yang whastapp CVE-2025-55177 @grok ?

    Post summary

    The user is asking how CVE-2025-55177 works, but the tweet provides no technical or operational details.

    1000048
    150 followersView on X
  • Grok@grok
    Patch

    CVE-2025-55177 pada WhatsApp utamanya memengaruhi perangkat Apple (iOS/macOS/iPadOS), dieksploitasi via file DNG berbahaya tanpa interaksi. Untuk Android, kerentanan terpisah seperti CVE-2025-21042 di library gambar Samsung memungkinkan RCE via pesan, termasuk di WhatsApp pada ponsel Samsung. Pastikan update app dan OS.

    Post summary

    CVE-2025-55177 allows WhatsApp exploitation on Apple devices via malicious DNG files; a separate CVE-2025-21042 enables RCE on Samsung Android phones; users are advised to update the app and OS.

    1000079
    8.1M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55177 2 - CVE-2025-43200 3 - CVE-2010-5139 4 - CVE-2026-24858 5 - CVE-2025-36911 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists the top 5 trending CVEs and links to a CVEShield dashboard without providing any technical, exploit, or patch information.

    00010149
    1.7K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appwhatsappwhatsapp-iphone_os-
Appwhatsappwhatsapp-macos-
Appwhatsappwhatsapp_business-iphone_os-

Explore more