cbcvebase.
CVE-2025-55179
published 2025-11-18

CVE-2025-55179: Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac…

PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.17%
6.2th percentile
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.

Affected

6 ranges
VendorProductVersion rangeFixed in
facebookwhatsapp_business_for_ios>= 2.25.8.14 < 2.25.23.822.25.23.82
facebookwhatsapp_desktop_for_mac>= 2.25.8.14 < 2.25.23.832.25.23.83
facebookwhatsapp_for_ios>= 2.25.8.17 < 2.25.23.732.25.23.73
whatsappwhatsapp>= 2.25.8.14 < 2.25.23.832.25.23.83
whatsappwhatsapp>= 2.25.8.17 < 2.25.23.732.25.23.73
whatsappwhatsapp_business>= 2.25.8.14 < 2.25.23.822.25.23.82
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.