#VU114603 Improper authorization in WhatsApp products - CVE-2025-55177
Published: September 1, 2025
WhatsApp Messenger for iOS
WhatsApp Business for iOS
WhatsApp for Mac
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authorization of linked device synchronization messages. A remote attacker can force the application to process content from an arbitrary URL on a target device.
Note, the vulnerability is being actively exploited in the wild in conjunction with #VU114314 (CVE-2025-43300).