Overview
- WhatsApp sent targeted warnings and urged immediate app and OS updates, specifying iOS version 2.25.21.73 and macOS version 2.25.21.78.
- The CVE-2025-55177 zero-click vulnerability can initiate URL content processing that installs malware or spyware without user interaction.
- Combined with Apple’s CVE-2025-43300, the exploit could enable deep access to devices and sensitive data, including messages.
- Meta reported that dozens of users were compromised during a roughly three-month window, and the attackers have not been publicly identified.
- Amnesty International cautioned that Android devices may also be affected and advised high-risk users to enable hardened protection modes or perform a factory reset.