Home

Description

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.

PUBLISHED Reserved 2025-08-08 | Published 2025-11-18 | Updated 2025-11-18 | Assigner Meta




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C

Problem types

Incorrect Authorization (CWE-863)

Product status

Default status
unknown

2.25.8.14 (semver) before 2.25.23.82
affected

Default status
unaffected

2.25.8.17 (semver) before 2.25.23.73
affected

Default status
unaffected

2.25.8.14 (semver) before 2.25.23.83
affected

References

www.facebook.com/security/advisories/cve-2025-55179

www.whatsapp.com/security/advisories/2025/

cve.org (CVE-2025-55179)

nvd.nist.gov (CVE-2025-55179)

Download JSON