Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
References
| Link | Resource |
|---|---|
| https://www.facebook.com/security/advisories/cve-2025-55179 | Vendor Advisory |
| https://www.whatsapp.com/security/advisories/2025/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
25 Nov 2025, 17:35
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Whatsapp
Whatsapp whatsapp Whatsapp whatsapp Business |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:macos:*:* cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:* |
|
| References | () https://www.facebook.com/security/advisories/cve-2025-55179 - Vendor Advisory | |
| References | () https://www.whatsapp.com/security/advisories/2025/ - Vendor Advisory |
18 Nov 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 15:16
Updated : 2025-11-25 17:35
NVD link : CVE-2025-55179
Mitre link : CVE-2025-55179
CVE.ORG link : CVE-2025-55179
JSON object : View
Products Affected
- whatsapp_business
CWE
