5.4
CVE-2025-55179
- EPSS 0.15%
- Veröffentlicht 18.11.2025 13:56:31
- Zuletzt bearbeitet 25.11.2025 17:35:13
- Quelle cve-assign@fb.com
- CVE-Watchlists
- Unerledigt
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.044 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve-assign@fb.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
https://www.whatsapp.com/security/advisories/2025/
https://www.facebook.com/security/advisories/cve-2025-55179