Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms

February 7, 2026

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»WhatsApp Patches Zero-Day, Zero-Click Flaw
Cyber Security

WhatsApp Patches Zero-Day, Zero-Click Flaw

Team-CWDBy Team-CWDSeptember 13, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


WhatsApp has patched a critical zero-day vulnerability it believes was exploited in a sophisticated attack.

The messaging giant revealed in a security advisory late last week that CVE-2025-55177 relates to “incomplete authorization of linked device synchronization messages.”

The firm added: “It could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.”

The Apple bug in question was described by the tech giant as an “out-of-bounds write issue” when it patched it on August 20.

“Processing a malicious image file may result in memory corruption,” it said at the time.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

Read more on WhatsApp bugs: Spyware Maker NSO Group Liable for WhatsApp User Hacks

Given the messaging from both firms, it’s highly likely that the bugs were exploited as part of a commercial spyware campaign. In fact, this was confirmed by Donncha Ó Cearbhaill, head of the security lab at Amnesty International, where he hunts for spyware used to target civil society.

In April 2023, for example, security researchers found a zero-click, zero-day exploit that targeted iPhone users with commercial spyware a couple of years previously. In that campaign, malware designed by secretive Israeli firm QuaDream was used.

These exploits are particularly dangerous as they require no user interaction to work, meaning victims are completely unaware that their every move is being watched. Once installed, spyware such as this, or the infamous Pegasus variant from NSO Group, is designed to access the device camera, microphone, messages, photos and much more.

NSO Group was ordered to pay $167m in damages earlier this year after a long-running legal battle with WhatsApp. It stemmed from a 2019 discovery that Pegasus had been used to target over a thousand WhatsApp users, including human rights activists, journalists and diplomats.  

CVE-2025-55177 impacts WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78 and WhatsApp for Mac v2.25.21.78.

Image credit: MardeFondos / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSimple Steps for Attack Surface Reduction
Next Article The hidden risks of browser extensions – and how to avoid them
Team-CWD
  • Website

Related Posts

Cyber Security

Why AI’s Rise Makes Protecting Personal Data More Critical Than Ever

February 6, 2026
Cyber Security

New Hacking Campaign Exploits Microsoft Windows WinRAR Vulnerability

February 5, 2026
Cyber Security

Two Critical Flaws Found in n8n AI Workflow Automation Platform

February 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

How the always-on generation can level up their cybersecurity game

September 11, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.