WhatsApp Fixes Zero-Day Bug Exploited in Targeted Spyware Attacks

  • WhatsApp fixed a significant security vulnerability that could affect iOS and macOS users.
  • The flaw, CVE-2025-55177, may have been used in real-world attacks combined with a separate Apple vulnerability.
  • The vulnerability allowed unauthorized users to trigger the processing of content from any URL on a target’s device.
  • Impacted versions include WhatsApp for iOS before 2.25.21.73, WhatsApp Business for iOS version 2.25.21.78, and WhatsApp for Mac version 2.25.21.78.
  • WhatsApp urged affected users to perform a full device reset and update their apps and operating systems.

WhatsApp has resolved a critical security issue impacting its messaging applications for Apple iOS and macOS. The company reported the vulnerability may have been actively exploited in combination with a recent Apple software flaw targeting specific users.

- Advertisement -

The vulnerability, tracked as CVE-2025-55177 with a severity score of 8.0 out of 10, involved insufficient authorization related to device synchronization messages. According to Meta, this security gap could permit an unrelated individual to make a target device process content from an arbitrary website address.

Meta listed affected software as WhatsApp for iOS versions before 2.25.21.73, WhatsApp Business for iOS version 2.25.21.78, and WhatsApp for Mac version 2.25.21.78. The company identified the issue internally and noted the vulnerability may have been combined with another Apple flaw, CVE-2025-43300, in targeted attacks. Apple recently disclosed CVE-2025-43300 as an out-of-bounds write flaw in the ImageIO framework, which could cause memory corruption when a malicious image is processed.

Amnesty International’s Security Lab head, Donncha Ó Cearbhaill, stated that WhatsApp notified a number of users believed to have been targets of an advanced spyware campaign in the past three months utilizing this vulnerability. In its alert to those affected, WhatsApp recommended a full device factory reset and keeping both WhatsApp and the device operating system updated for optimal protection.

Ó Cearbhaill described the two weaknesses as a “zero-click” attack, meaning the victim’s device could be compromised without any action, such as clicking a link. He explained, “Early indications are that the WhatsApp attack is impacting both iPhone and Android users, civil society individuals among them.” He added that government spyware remains a significant threat to journalists and human rights defenders.

- Advertisement -

It is currently unknown which group or company may be responsible for these attacks, and WhatsApp has not released any specific information about the perpetrators.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

XRP Eyes Rally as ETFs and Buy Signal Boost 2026 Hopes Surge

Ripple settled its US lawsuit in 2025, helping XRP reach a $3.65 all-time high...

Bitfinex Hacker Ilya Lichtenstein Freed Early via First Step

Ilya Lichtenstein was released from prison after serving 14 months of a five-year sentence...

Waymo’s 2026 Expansion Could Drive Big Gains for GOOGL Surge

Alphabet rallied more than 60% in 2025 and enters 2026 with investor optimism tied...

Tesla shares slip as Q4 deliveries deemed largely neutral US

Tesla delivered 418,227 vehicles in Q4, slightly below the 422,850 company-polled consensus and last...

Institutions Pour In: 2026 Poised to Ignite ETH Value Rise!!

Ethereum insiders say 2026 could trigger significant ETH value growth as institutions increase on-chain...
- Advertisement -

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Bitcoin (BTC) $ 89,913.00 1.92%
Ethereum (ETH) $ 3,122.71 4.50%
XRP (XRP) $ 1.99 6.52%
Bittensor (TAO) $ 245.42 8.02%
Polkadot (DOT) $ 2.12 6.40%
Cardano (ADA) $ 0.388114 8.36%
Chainlink (LINK) $ 13.28 6.06%
Hyperliquid (HYPE) $ 24.58 0.76%
Monero (XMR) $ 419.74 0.04%
Hedera (HBAR) $ 0.120309 6.40%
Toncoin (TON) $ 1.81 6.80%