CVE detail
CVE-2025-55177
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
17 source links · newest first
- Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No WarningSecurity Affairs
A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction. There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the “Linked […]
newssecurityaffairs.comMay 25, 2026, 10:29 AM - CISA: Spyware and RATs used to target WhatsApp and Signal UsersSecurity Affairs
CISA warns that threat actors are actively using commercial spyware and RATs to target users of mobile messaging apps WhatsApp and Signal. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of threat actors using commercial spyware and remote access trojans (RATs) to target users of popular instant messaging applications, including WhatsApp and Signal. […]
newssecurityaffairs.comNov 25, 2025, 10:39 AM Threat actors exploited CVE-2025-21042 to deliver malware via specially crafted images to users in the Middle East.
newswww.securityweek.comNov 7, 2025, 3:29 PMCommercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.
vendorunit42.paloaltonetworks.comNov 7, 2025, 11:00 AMIn light of new memory safety features added to Apple’s latest iPhone chips that make entire classes of exploits harder to pull off, the company has revamped its bug bounty program to double or quadruple rewards in various attack categories. The payout for an iOS zero-click system-level remote code execution (RCE) exploit responsibly disclosed to […]
newswww.csoonline.comOct 10, 2025, 7:27 PM- Apple backports fix for actively exploited CVE-2025-43300Security Affairs
Apple announced it has backported patches for a recently addressed actively exploited vulnerability tracked as CVE-2025-43300. Apple has backported security patches released to address an actively exploited vulnerability tracked as CVE-2025-43300. In August 2025, Apple addressed the actively exploited zero-day CVE-2025-43300 in iOS, iPadOS, and macOS. The vulnerability is zero-day out-of-bounds write issue that resides […]
newssecurityaffairs.comSep 17, 2025, 5:24 AM Reported by Meta and WhatsApp, the vulnerability leads to remote code execution and was likely exploited by a spyware vendor.
newswww.securityweek.comSep 15, 2025, 8:08 AM- Samsung fixed actively exploited zero-daySecurity Affairs
Samsung fixed the remote code execution flaw CVE-2025-21043 that was exploited in zero-day attacks against Android devices. Samsung addressed the remote code execution vulnerability, tracked as CVE-2025-21043, that was exploited in zero-day attacks against Android users. The vulnerability is an out-of-bounds Write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1. A remote attacker can exploit […]
newssecurityaffairs.comSep 12, 2025, 11:44 AM - 8th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 8th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES A supply chain breach involving Salesloft’s Drift integration to Salesforce exposed sensitive customer data from multiple organizations, including Cloudflare, Zscaler, Palo Alto Networks, and Workiva. The attackers accessed Salesforce CRM systems via […]
vendorresearch.checkpoint.comSep 8, 2025, 11:05 AM - U.S. CISA adds WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: CVE-2020-24363 (CVSS 8.8) is a missing authentication flaw in TP-Link TL-WA855RE […]
newssecurityaffairs.comSep 3, 2025, 12:09 PM The vulnerability (CVE-2025-55177) was exploited along an iOS/macOS zero-day in suspected spyware attacks.
newswww.securityweek.comSep 2, 2025, 11:39 AM- WhatsApp fixes vulnerability used in zero-click attacksMalwarebytes Labs
WhatsApp has patched a vulnerability that was used in conjunction with an Apple vulnerability in zero-click attacks.
newswww.malwarebytes.comSep 1, 2025, 1:55 PM - 1st September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 1st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES American consumer credit reporting agency TransUnion has suffered a data breach that resulted in the exposure of sensitive personal information for over 4.4 million individuals in the United States. The leaked data […]
vendorresearch.checkpoint.comSep 1, 2025, 11:50 AM - New zero-click exploit allegedly used to hack WhatsApp usersSecurity Affairs
WhatsApp warns users targeted by advanced spyware, sending threat notifications to affected individuals from the past 90 days. A new zero-click exploit used to hack WhatsApp users, reported Donncha Ó Cearbhaill, Head of Security Lab at @AmnestyTech. WhatsApp has just sent out a round of threat notifications to individuals they believe were targeted by an […]
newssecurityaffairs.comAug 29, 2025, 9:53 PM No excerpt available.
Mitigationwww.cisa.govAug 29, 2025, 4:15 PM- https://www.whatsapp.com/security/advisories/2025/www.whatsapp.com
No excerpt available.
Vendor Advisorywww.whatsapp.comAug 29, 2025, 4:15 PM - https://www.facebook.com/security/advisories/cve-2025-55177www.facebook.com
No excerpt available.
Vendor Advisorywww.facebook.comAug 29, 2025, 4:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-55179CVSS 5.4 · Medium
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowe…
2 mentions - CVE-2022-36934CVSS 9.8 · Critical
An integer overflow in WhatsApp could result in remote code execution in an established video call.
- CVE-2021-24043CVSS 9.1 · Critical
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business…
- CVE-2021-24041CVSS 9.8 · Critical
A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a…
- CVE-2021-24035CVSS 9.1 · Critical
A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attac…
- CVE-2021-24027CVSS 7.5 · High
A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s extern…