5.4

CVE-2025-55179

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WhatsAppWhatsApp SwPlatformmacos Version >= 2.25.8.14 < 2.25.23.83
WhatsAppWhatsApp SwPlatformiphone_os Version >= 2.25.8.17 < 2.25.23.73
WhatsAppWhatsApp Business SwPlatformiphone_os Version >= 2.25.8.14 < 2.25.23.82
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.044
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve-assign@fb.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.whatsapp.com/security/advisories/2025/
Vendor Advisory
https://www.facebook.com/security/advisories/cve-2025-55179
Vendor Advisory