Vulnerability details
Advisory: SB2025090130 - Improper authorization in WhatsApp for iOS and macOS
Vulnerable component: WhatsApp for Mac
CVE-ID: CVE-2025-55177
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C
CWE-ID: CWE-285 - Improper Authorization
Description:
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authorization of linked device synchronization messages. A remote attacker can force the application to process content from an arbitrary URL on a target device.
Note, the vulnerability is being actively exploited in the wild in conjunction with #VU114314 (CVE-2025-43300).
External links:
https://www.facebook.com/security/advisories/cve-2025-55177