WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability

WhatsApp on Friday announced it patched a zero-day vulnerability it believes was used to launch sophisticated attacks against specific individuals.

The Meta-owned messaging platform said in a security advisory that the bug, labeled CVE-2025-55177, involves “incomplete authorization of linked device synchronization messages.”

The issue “could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device,” the advisory says. 

WhatsApp believes the vulnerability could have been combined with a separate OS-level vulnerability on Apple devices (CVE-2025-43300) to potentially launch sophisticated attacks against “specific targeted users,” the advisory says.

Apple, which patched CVE-2025-43300 on August 20, has described it as an “out-of-bounds write issue.” 

The tech giant said it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

CVE-2025-43300 affected Apple’s iOS, iPadOS and macOS products.

No technical details were released by either company.

In 2019, WhatsApp was exploited with a zero-day attack carried out by the NSO Group, which manufactures the zero-click spyware known as Pegasus. That attack impacted some 1,400 Apple users and resulted in a court finding holding NSO Group liable. 

In January WhatsApp accused a separate spyware company, Paragon, of targeting about 90 of its users with spyware. Digital forensic experts from the Citizen Lab subsequently verified some of those attacks occurred.

CybercrimeNewsMalwareNews BriefsTechnology
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.

 

Total
0
Shares
Previous Post

Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control

Next Post

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

Related Posts

U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust

A Chinese national has been convicted for her role in a fraudulent cryptocurrency scheme after law enforcement authorities in the U.K. confiscated £5.5 billion (about $7.39 billion) during a raid of her home in London. The cryptocurrency seizure, amounting to 61,000 Bitcoin, is believed to be the single largest such effort in the world, the Metropolitan Police said. Zhimin Qian (aka Yadi Zhang),
Read More

Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets

The Iranian state-sponsored threat actor known as APT42 has been observed targeting individuals and organizations that are of interest to the Islamic Revolutionary Guard Corps (IRGC) as part of a new espionage-focused campaign. The activity, detected in early September 2025 and assessed to be ongoing, has been codenamed SpearSpecter by the Israel National Digital Agency (INDA). "The
Read More

Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors

Anthropic on Wednesday revealed that it disrupted a sophisticated operation that weaponized its artificial intelligence (AI)-powered chatbot Claude to conduct large-scale theft and extortion of personal data in July 2025. "The actor targeted at least 17 distinct organizations, including in healthcare, the emergency services, and government, and religious institutions," the company said. "
Read More