// 2 CRITICAL · 3 ZERO-DAY · 2 CVE IN THE LAST 24H
WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices sync messages. The vulnerability was actively exploited in zero-click attacks targeting journalists and human rights defenders. The CVSS 3.1 score of 5.4 (Medium) fails to capture the operational risk: chained with Apple's CVE-2025-43300, it enabled processing of arbitrary URL content without victim interaction. WhatsApp sent in-app notifications to fewer than 200 users, recommending a full factory reset for notified targets.

WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization vulnerability in Linked Devices sync messages. The flaw fueled active zero-click attacks against journalists and human rights defenders. The CVSS 3.1 score of 5.4, rated Medium by the National Vulnerability Database, does not reflect the active exploitation context: combined with Apple's CVE-2025-43300, it allowed processing of content from arbitrary URLs without any victim interaction. WhatsApp sent in-app notifications to fewer than 200 users, recommending a full factory reset for notified targets.

Source Limitations: Converging primary structured sources are essentially one: The Hacker News, with NVD as the formal CVE record. CyberPress.org provides independent forensic details from Forenser with an anomalous publication date (2026-05-27), not independently verified and not cited by other sources. Amnesty International is cited through The Hacker News, not via an independent advisory.

Key Takeaways
  • CVE-2025-55177 is classified CWE-863 (Incorrect Authorization) with CVSS 5.4, but was exploited in-the-wild chained with Apple flaw CVE-2025-43300 for zero-click attacks
  • Patched versions: WhatsApp for iOS 2.25.21.73 (July 28, 2025), WhatsApp Business for iOS 2.25.21.78, and WhatsApp for Mac 2.25.21.78 (August 4, 2025)
  • Amnesty International Security Lab confirms the campaign targeted civil society individuals, journalists, and human rights defenders over a roughly 90-day window
  • CISA added CVE-2025-55177 to the Known Exploited Vulnerabilities catalog with a mitigation deadline of September 23, 2025

The Attack Mechanism: Invisible Resync and Arbitrary URLs

FACT: The vulnerability resides in synchronization messages between devices linked to a WhatsApp account. According to the official WhatsApp/Meta description reported by The Hacker News, the flaw "could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target's device". An attacker could force the target device to process content from a controlled URL, bypassing authorization checks intended for Linked Devices.

FACT: According to a Forenser analysis published on CyberPress.org — with an anomalous date of May 27, 2026, not independently verified — the attacker's session was not registered as a traditional Linked Device. The target device would have shown a continuous stream of resync events, invisible in the linked devices management interface.

EDITORIAL ANALYSIS: If confirmed, this pattern would make compromise difficult to detect through standard user checks. The source does not specify whether the Forenser analysis was published concurrently with or after the incident.

FACT: The chain is completed by CVE-2025-43300, an out-of-bounds write in Apple's ImageIO framework. The WhatsApp vulnerability provided the initial vector for arbitrary URL processing; the Apple flaw enabled escalation of the compromise. Apple described CVE-2025-43300 as an "extremely sophisticated attack against specific targeted individuals" — attribution referring to the Apple flaw, not the WhatsApp attack generally.

"Early indications are that the WhatsApp attack is impacting both iPhone and Android users, civil society individuals among them" — Donncha Ó Cearbhaill, head of Security Lab at Amnesty International

The CVSS 5.4: Facts and Operational Context

FACT: The CVSS 3.1 score of 5.4 for CVE-2025-55177 reflects the attack vector: network, low complexity, low privileges, no user interaction, unchanged scope, limited impact on confidentiality and integrity, no availability impact. This formal classification is technically correct for the isolated vulnerability. The National Vulnerability Database reports the qualifier "NVD assessment not yet provided" for CVSS 4.0.

EDITORIAL ANALYSIS: The score does not capture operational risk when the flaw is embedded in an exploit chain. CISA's KEV catalog, which lists actively exploited vulnerabilities regardless of score, serves in this case as a more relevant operational alert. The September 23, 2025 mitigation deadline set by CISA is binding for U.S. federal agencies.

WhatsApp's Response and the Factory Reset

FACT: WhatsApp adopted direct communication with targets: in-app notifications to "less than 200 users who may have been targeted", recommending a full device factory reset. The recommendation was limited to notified targets. WhatsApp did not publish a standalone technical advisory directly linkable.

EDITORIAL ANALYSIS: The source does not specify whether the factory reset indicates compromise beyond the app boundary. The recommendation may reflect caution proportionate to the targets' risk profile, not necessarily evidence of system or host compromise.

FACT: Patched versions are available for iOS and macOS; the brief does not document release notes detailing the fix. Donncha Ó Cearbhaill of Amnesty International confirmed that "government spyware continues to pose a threat to journalists and human rights defenders", placing the incident in the broader context of commercial surveillance campaigns.

What to Do Now

FACT: For users within the target group notified by WhatsApp, the platform recommended a full device factory reset. For all other WhatsApp users on iOS and macOS, documented actions in the brief are limited to updating:

  • Update to WhatsApp for iOS 2.25.21.73 or later, or WhatsApp Business for iOS 2.25.21.78 or later
  • Update WhatsApp for Mac to version 2.25.21.78 or later

FACT: For organizations, CISA set a September 23, 2025 mitigation deadline for U.S. federal agencies via the KEV catalog. The source does not specify further operational actions for non-targeted users.

Editorial Close

CVE-2025-55177 illustrates a structural tension in risk assessment: a CVSS 5.4 rated Medium can mask high operational impact when the vulnerability is weaponized in a targeted exploit chain. WhatsApp's response — emergency update, direct notifications, factory reset for targets — signals perceived severity independent of the formal metric.

Unverified remain the identity of the vendor or threat actor group, any Android impact with an identical mechanism, and validation of the Forenser analysis publication date. The factory reset recommendation, limited to notified targets, does not constitute proof of system compromise: the source does not specify the extent of compromise beyond application boundaries.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com
  2. nvd.nist.gov
  3. cyberpress.org