Medium severity5.4NVD Advisory· Published Nov 18, 2025· Updated Jun 17, 2026
CVE-2025-55179
CVE-2025-55179
Description
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*+ 1 more
- cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*range: >=2.25.8.14,<2.25.23.82
- (no CPE)range: <2.25.23.82
- Range: <2.25.23.83
- Range: <2.25.23.73
- Range: 2.25.8.14
- Range: 2.25.8.14
- Range: 2.25.8.17
Patches
Vulnerability mechanics
References
2- www.facebook.com/security/advisories/cve-2025-55179nvdVendor Advisory
- www.whatsapp.com/security/advisories/2025/nvdVendor Advisory
News mentions
0No linked articles in our index yet.