CVE-2025-55177

9.5 CISA KEV

Meta Platforms · WhatsApp

WhatsApp exhibits an incorrect authorization flaw in linked device synchronization, allowing unauthorized processing of content from arbitrary URLs when combined with specific Apple OS vulnerabilities.

Executive summary

Meta Platforms has confirmed that this critical authorization vulnerability in WhatsApp is being actively exploited in the wild, necessitating immediate patching to protect user data and device integrity.

Vulnerability

This flaw involves incorrect authorization of linked device synchronization messages, which permits an authenticated user to force a target device to process content from an attacker-controlled URL. The vulnerability requires interaction with a secondary OS-level exploit to achieve full impact.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational confidentiality and device security. By leveraging this flaw to process arbitrary content, attackers may facilitate sophisticated targeted surveillance or data exfiltration against high-value users. Given the CVSS score of 9.5 and confirmed active exploitation, the risk of reputational and operational damage is extreme.

Remediation

Immediate Action: Update all instances of WhatsApp on iOS and macOS to the latest available versions, specifically ensuring the software is patched to at least version 2.25.21.73 for standard iOS and 2.25.21.78 for Business and Mac.

Proactive Monitoring: Monitor device traffic for unusual outbound connections to unknown domains originating from WhatsApp, especially following the receipt of unexpected messages.

Compensating Controls: Ensure that mobile device management (MDM) policies are strictly enforced to prevent unauthorized application installations and to maintain current OS-level security patches, which are required to mitigate the secondary exploit vector.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.

Analyst recommendation

Due to the critical severity and confirmed status of this vulnerability in the CISA Known Exploited Vulnerabilities catalog, immediate remediation is mandatory. Organizations must prioritize updating all WhatsApp installations across their mobile and desktop fleets to ensure protection against ongoing, sophisticated campaigns. Failure to patch will leave affected devices vulnerable to targeted exploitation and potential compromise.

More Meta Platforms CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section, carried in 2 daily briefs, Aug 29 to Aug 30
  3. Published in the daily brief kev section, carried in 20 daily briefs, Sep 2 to Sep 22
  4. Analyst report written
  5. Fix documented version 2.25.21.78 per CVE record

Sources