On August 30, 2025, WhatsApp issued an emergency patch for a high‑severity vulnerability tracked as CVE‑2025‑55177 in its iOS and macOS applications, amid signs that it may have been exploited in targeted attacks. The fix arrives in response to a sophisticated attack vector that potentially affected specific individuals, including civil society representatives.

What is CVE-2025-55177?

This zero‑day vulnerability, scored 8.0 on the CVSS scale, stems from insufficient authorization in linked device synchronization messages. WhatsApp’s internal security team discovered and reassessed the bug, noting that it could allow an unrelated user to trigger the processing of content from an arbitrary URL on a victim’s device—even without any user interaction.

This elevated the risk significantly, as the flaw belongs to the dreaded “zero‑click” class of exploits—attacks where the victim need not click anything to be compromised.

Chained Exploits: Apple’s ImageIO Flaw

Compounding the threat, WhatsApp assessed that the bug may have been exploited in tandem with another vulnerability—CVE‑2025‑43300—disclosed by Apple only a week earlier. This Apple flaw, related to an out‑of‑bounds write in the ImageIO framework, could enable memory corruption when processing a malicious image, especially on iOS, iPadOS, and macOS systems.

When combined, these two vulnerabilities create a deadly chain: WhatsApp’s synchronization bug opening the door, and the ImageIO flaw delivering the payload.

Affected Versions and Recommended Actions

WhatsApp specifically identified vulnerable app versions:

  • WhatsApp for iOS prior to version 2.25.21.73
  • WhatsApp Business for iOS, version 2.25.21.78
  • WhatsApp for macOS, version 2.25.21.78

The company has not disclosed the number of users impacted but confirmed it notified those believed to have been targeted. In its alerts, WhatsApp urged recipients to perform a full device factory reset and ensure both their operating system and WhatsApp app are fully updated.

Targeted Attacks and Civil Society Implications

Donncha Ó Cearbhaill, head of Amnesty International’s Security Lab, linked the vulnerability to a highly targeted spyware campaign conducted over the past 90 days. He noted that both iPhone and Android users, especially members of civil society, appear to have been targets of the exploit(s). Moreover, early indications suggest that apps beyond WhatsApp could also have been compromised in the campaign.

This context underscores a troubling reality: even widely trusted communication platforms can be weaponized against vulnerable individuals, particularly those in journalism, activism, and human rights.

Lessons and Takeaways

  1. Zero-Click Attacks Are a Serious Threat
    These exploits bypass typical user protection layers like phishing awareness or cautious clicking, making them especially dangerous.
  2. Patch Fast, Patch First
    Staying current with app and OS updates is essential—especially when high-severity vulnerabilities emerge.
  3. Targeted Campaigns Demand Proactive Defense
    Activists, journalists, and civil society actors remain high-value targets. Threat modeling should account for advanced spyware and zero-click tactics.
  4. Factory Resets Can Help, But Prevention Is Key
    Although WhatsApp advises a full reset for confirmed targets, maintaining secure posture is better than remediation post-compromise.

Summary

On August 30, 2025, WhatsApp urgently addressed CVE-2025-55177, a “zero-click” vulnerability in its iOS and macOS apps that may have been exploited in the wild, possibly in coordination with Apple’s ImageIO flaw CVE-2025-43300. The company patched affected versions, advised impacted users to reset devices, and emphasized updating all software. The incident highlights ongoing risks to civil society actors, reminding us of the evolving sophistication in cyberespionage.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *