logo

WhatsApp fixes vulnerability used in zero-click attacks

ID: 1c827096-d7d4-5179-96d4-228b2196f614

STIX ID: report--1c827096-d7d4-5179-96d4-228b2196f614

Feed Name: Malwarebytes Blog

Threat Score
85/100

Date Published: 2025-09-01

Date Updated: 2026-04-28

...
...

A zero-click exploitation chain combined an out-of-bounds write in Apple Image I/O (CVE-2025-43300) with a WhatsApp linked-device sync authorization flaw (CVE-2025-55177) to compromise iOS/macOS devices and deliver spyware; WhatsApp has patched affected app versions, notified dozens of users, and advised full device factory resets while Apple issued fixes for Image I/O. The report explains the technical memory-corruption and sync-processing issues, notes Android was mentioned but that the most severe risk applied to Apple devices, and recommends updating apps/OS and following WhatsApp's remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.