CVE-2025-55179
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-11-25
Assigner: Facebook, Inc.
Description
Description
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another userβs device. We have not seen evidence of exploitation in the wild.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| From 2.25.8.14 (inc) to 2.25.23.83 (exc) | ||
| From 2.25.8.17 (inc) to 2.25.23.73 (exc) | ||
| whatsapp_business | From 2.25.8.14 (inc) to 2.25.23.82 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |