logo

New Zero-Click WhatsApp Account Takeover Attack Targets iOS 16 Users

ID: 44a98488-d070-5479-b162-f3854744dbe6

STIX ID: report--44a98488-d070-5479-b162-f3854744dbe6

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Divya

...
...

A newly uncovered zero-click campaign exploited two vulnerabilities (CVE-2025-43300 in Apple ImageIO and CVE-2025-55177 in WhatsApp) on iOS 16 devices to silently hijack WhatsApp accounts and send fraudulent money requests; forensic analysis found continuous resynchronization log patterns indicative of a hidden secondary client, and mitigation is to update iOS and WhatsApp or reinstall/move the account.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.