CVE-2025-55177Medium· 5.4▾ Midnight⚠ Exploited in the wildPoC availableIncomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processi…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 29.7 · likelihood 0.9 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 23, 2025
Last analysed / modified upstream
4.7%
1 GitHub repo (last check)
Added to the CISA catalog on Sep 2, 2025. Federal remediation due Sep 23, 2025. View catalog ↗
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
whatsapp >= 2.22.25.2, < 2.25.21.73whatsapp >= 2.22.25.2, < 2.25.21.78whatsapp_business >= 2.22.25.2, < 2.25.21.78Upgrade past the affected range:
whatsapp 2.25.21.78whatsapp_business 2.25.21.78Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100532High· 8.1@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced
CVE-2025-67740Low· 2.7In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
CVE-2026-105797High· 8.8SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
CVE-2026-105703Medium· 4.7A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3
CVE-2026-105786High· 8.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-105129Medium· 6.5LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API