CVE-2025-55177
Description
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Summary dbcve.org
This is an incomplete authorization vulnerability in WhatsApp's linked device synchronization feature. An unrelated user could trick a target's device into processing content from an arbitrary URL by sending specially crafted synchronization messages. The flaw exists in the message validation logic for linked device sync, allowing authorization checks to be bypassed.
Mitigation
Update WhatsApp for iOS to v2.25.21.73 or later, WhatsApp Business for iOS to v2.25.21.78 or later, and WhatsApp for Mac to v2.25.21.78 or later. Organizations should also address the complementary OS vulnerability (CVE-2025-43300) on Apple platforms.