cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:iphone_os:*:*, +1 more
- < 2.25.21.73
- < 2.25.21.78
This vulnerability is being actively exploited in the wild.
A vulnerability exists in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78, due to incomplete authorization of linked device synchronization messages. This vulnerability could have allowed an unrelated user to initiate the processing of content from an arbitrary URL on a target device. It is believed that this issue, combined with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against certain targeted users.
Exploitation of this vulnerability could have led to unauthorized processing of content from arbitrary URLs on the affected user's device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.