Skip to main content

CVE detail

CVE-2025-55177

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

CVSS 5.4 · MediumBuzz score 73.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 73.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
28.9
17 evidence mentions in the snapshot
Diversity score
20.0
9 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
17 source links · newest first
  • A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction. There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the “Linked […]

    newssecurityaffairs.comMay 25, 2026, 10:29 AM
  • CISA warns that threat actors are actively using commercial spyware and RATs to target users of mobile messaging apps WhatsApp and Signal. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of threat actors using commercial spyware and remote access trojans (RATs) to target users of popular instant messaging applications, including WhatsApp and Signal. […]

    newssecurityaffairs.comNov 25, 2025, 10:39 AM
  • Threat actors exploited CVE-2025-21042 to deliver malware via specially crafted images to users in the Middle East.

    newswww.securityweek.comNov 7, 2025, 3:29 PM
  • Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.

    vendorunit42.paloaltonetworks.comNov 7, 2025, 11:00 AM
  • In light of new memory safety features added to Apple’s latest iPhone chips that make entire classes of exploits harder to pull off, the company has revamped its bug bounty program to double or quadruple rewards in various attack categories. The payout for an iOS zero-click system-level remote code execution (RCE) exploit responsibly disclosed to […]

    newswww.csoonline.comOct 10, 2025, 7:27 PM
  • Apple announced it has backported patches for a recently addressed actively exploited vulnerability tracked as CVE-2025-43300. Apple has backported security patches released to address an actively exploited vulnerability tracked as CVE-2025-43300. In August 2025, Apple addressed the actively exploited zero-day CVE-2025-43300 in iOS, iPadOS, and macOS. The vulnerability is zero-day out-of-bounds write issue that resides […]

    newssecurityaffairs.comSep 17, 2025, 5:24 AM
  • Reported by Meta and WhatsApp, the vulnerability leads to remote code execution and was likely exploited by a spyware vendor.

    newswww.securityweek.comSep 15, 2025, 8:08 AM
  • Samsung fixed actively exploited zero-daySecurity Affairs

    Samsung fixed the remote code execution flaw CVE-2025-21043 that was exploited in zero-day attacks against Android devices. Samsung addressed the remote code execution vulnerability, tracked as CVE-2025-21043, that was exploited in zero-day attacks against Android users. The vulnerability is an out-of-bounds Write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1. A remote attacker can exploit […]

    newssecurityaffairs.comSep 12, 2025, 11:44 AM
  • 8th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 8th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES A supply chain breach involving Salesloft’s Drift integration to Salesforce exposed sensitive customer data from multiple organizations, including Cloudflare, Zscaler, Palo Alto Networks, and Workiva. The attackers accessed Salesforce CRM systems via […]

    vendorresearch.checkpoint.comSep 8, 2025, 11:05 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: CVE-2020-24363 (CVSS 8.8) is a missing authentication flaw in TP-Link TL-WA855RE […]

    newssecurityaffairs.comSep 3, 2025, 12:09 PM
  • The vulnerability (CVE-2025-55177) was exploited along an iOS/macOS zero-day in suspected spyware attacks.

    newswww.securityweek.comSep 2, 2025, 11:39 AM
  • WhatsApp has patched a vulnerability that was used in conjunction with an Apple vulnerability in zero-click attacks.

    newswww.malwarebytes.comSep 1, 2025, 1:55 PM
  • 1st September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 1st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES American consumer credit reporting agency TransUnion has suffered a data breach that resulted in the exposure of sensitive personal information for over 4.4 million individuals in the United States. The leaked data […]

    vendorresearch.checkpoint.comSep 1, 2025, 11:50 AM
  • WhatsApp warns users targeted by advanced spyware, sending threat notifications to affected individuals from the past 90 days. A new zero-click exploit used to hack WhatsApp users, reported Donncha Ó Cearbhaill, Head of Security Lab at @AmnestyTech. WhatsApp has just sent out a round of threat notifications to individuals they believe were targeted by an […]

    newssecurityaffairs.comAug 29, 2025, 9:53 PM
  • No excerpt available.

    Mitigationwww.cisa.govAug 29, 2025, 4:15 PM
  • No excerpt available.

    Vendor Advisorywww.whatsapp.comAug 29, 2025, 4:15 PM
  • No excerpt available.

    Vendor Advisorywww.facebook.comAug 29, 2025, 4:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence