Junglewise Threat Intelligence

CVE-2025-55177: Meta WhatsApp incorrect authorization in linked device synchronization

CVE-2025-55177 · Severity: critical · CVSS 5.4 · Exploited in the wild · Published 2025-09-02

Technologies: Meta Platforms WhatsApp, Meta WhatsApp for iOS. Vendors: Meta, Meta Platforms.

Executive brief

A vulnerability in WhatsApp for Apple devices could allow an attacker to force the app to process content from a malicious web address. This issue stems from how the app synchronizes messages between linked devices. When combined with other system-level flaws, this could be used in highly targeted attacks to compromise a user's device.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in WhatsApp for iOS and macOS due to incomplete validation of linked device synchronization messages. A remote attacker with basic user privileges can send specially crafted synchronization messages that bypass authorization checks, forcing the target's device to fetch and process content from an arbitrary URL. While the CVSS score provided by the vendor is medium (5.4), the vulnerability has been observed in the wild being chained with an Apple OS-level vulnerability (CVE-2025-43300) to perform sophisticated targeted attacks. Patches are available in WhatsApp for iOS v2.25.21.73 and WhatsApp Business/Mac v2.25.21.78.

Affected products

  • Meta WhatsApp for iOS prior to v2.25.21.73
  • Meta WhatsApp Business for iOS prior to v2.25.21.78
  • Meta WhatsApp for Mac prior to v2.25.21.78

Timeline

  • 2025-08-29: disclosed
  • 2025-08-29: advisory
  • 2025-09-02: kev added: Added to CISA KEV catalog due to active exploitation.

Related threats