Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:macos:*:* cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Facebook
Facebook facebook Whatsapp whatsapp Whatsapp whatsapp Business |
|
| Vendors & Products |
Facebook
Facebook facebook Whatsapp whatsapp Whatsapp whatsapp Business |
Tue, 18 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Meta
Published: 2025-11-18T13:56:31.598Z
Updated: 2025-11-18T14:25:08.232Z
Reserved: 2025-08-08T18:21:47.119Z
Link: CVE-2025-55179
Updated: 2025-11-18T14:25:03.625Z
Status : Analyzed
Published: 2025-11-18T15:16:32.177
Modified: 2025-11-25T17:35:13.610
Link: CVE-2025-55179
No data.