MEDIUM

CVE-2025-55177

Whatsapp Whatsapp 2025-08-29 CVSS v3.1
CVSS
5.4
KEV

Description

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

Summary dbcve.org

This is an incomplete authorization vulnerability in WhatsApp's linked device synchronization feature. An unrelated user could trick a target's device into processing content from an arbitrary URL by sending specially crafted synchronization messages. The flaw exists in the message validation logic for linked device sync, allowing authorization checks to be bypassed.

Mitigation

Update WhatsApp for iOS to v2.25.21.73 or later, WhatsApp Business for iOS to v2.25.21.78 or later, and WhatsApp for Mac to v2.25.21.78 or later. Organizations should also address the complementary OS vulnerability (CVE-2025-43300) on Apple platforms.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

4.3%
Probability of exploitation in next 30 days
90.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE