Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
References
| Link | Resource |
|---|---|
| https://www.facebook.com/security/advisories/cve-2025-55179 | Vendor Advisory |
| https://www.whatsapp.com/security/advisories/2025/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-11-18 15:16
Updated : 2025-11-25 17:35
NVD link : CVE-2025-55179
Mitre link : CVE-2025-55179
CVE.ORG link : CVE-2025-55179
JSON object : View
Products Affected
- whatsapp_business
CWE
