5.4

CVE-2025-55179

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WhatsAppWhatsApp SwPlatformmacos Version >= 2.25.8.14 < 2.25.23.83
WhatsAppWhatsApp SwPlatformiphone_os Version >= 2.25.8.17 < 2.25.23.73
WhatsAppWhatsApp Business SwPlatformiphone_os Version >= 2.25.8.14 < 2.25.23.82
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve-assign@fb.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N