Zero-day vulnerability in WhatsApp for Mac

Improper authorization
CVE-2025-55177

Vulnerability details

Advisory: SB2025090130 - Improper authorization in WhatsApp for iOS and macOS

Vulnerable component: WhatsApp for Mac

CVE-ID: CVE-2025-55177

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C

CWE-ID: CWE-285 - Improper Authorization

Description:

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper authorization of linked device synchronization messages. A remote attacker can force the application to process content from an arbitrary URL on a target device.

Note, the vulnerability is being actively exploited in the wild in conjunction with #VU114314 (CVE-2025-43300).

External links:

https://www.facebook.com/security/advisories/cve-2025-55177