Input validation error in WhatsApp products - CVE-2025-55179

 

Input validation error in WhatsApp products - CVE-2025-55179

Published: November 20, 2025


Vulnerability identifier: #VU118645
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55179
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient validation of rich response messages. A remote attacker can send a specially crafted message that will trigger processing of media content from an arbitrary URL on another user’s device.


Affected software

WhatsApp Messenger for iOS
WhatsApp Business for iOS
WhatsApp for Mac

How to mitigate CVE-2025-55179

Install updates from vendor's website.

WhatsApp Messenger for iOS - update to 25.23.73
WhatsApp Business for iOS - update to 2.25.23.82
WhatsApp for Mac - update to 2.25.23.83

External References

Related Security Bulletins