Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning
ID: d5cc0967-8476-5c20-95fb-a5a682f23bae
STIX ID: report--d5cc0967-8476-5c20-95fb-a5a682f23bae
Feed Name: Security Affairs
Threat Score
A zero-click exploit chain against iPhones on iOS 16 (linked to CVE-2025-43300 in ImageIO and CVE-2025-55177 in WhatsApp) has been used in the wild to exfiltrate WhatsApp session material and spawn remote clients that send fraudulent money requests while leaving no visible linked devices; Forenser confirmed active exploitation in Italy, reproduced the attack, and recommends immediate iOS and WhatsApp updates, chat locks, or reinstalling WhatsApp to evict attacker sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
