CVE-2025-55177
MEDIUM KEVWhatsapp < 2.25.21.73 - Incorrect Authorization
Title source: ruleDescription
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0073
EPSS Percentile
72.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
CISA KEV
2025-09-02
VulnCheck KEV
2025-08-20
ENISA EUVD
EUVD-2025-26214
CWE
CWE-863
Status
published
Products (3)
whatsapp/whatsapp
2.22.25.2 - 2.25.21.73
whatsapp/whatsapp
2.22.25.2 - 2.25.21.78
whatsapp/whatsapp_business
2.22.25.2 - 2.25.21.78
Published
Aug 29, 2025
KEV Added
Sep 02, 2025
Tracked Since
Feb 18, 2026