Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Facebook
Facebook facebook Whatsapp whatsapp Whatsapp whatsapp Business |
|
| Vendors & Products |
Facebook
Facebook facebook Whatsapp whatsapp Whatsapp whatsapp Business |
Tue, 18 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Meta
Published:
Updated: 2025-11-18T14:25:08.232Z
Reserved: 2025-08-08T18:21:47.119Z
Link: CVE-2025-55179
Updated: 2025-11-18T14:25:03.625Z
Status : Awaiting Analysis
Published: 2025-11-18T15:16:32.177
Modified: 2025-11-19T19:15:16.750
Link: CVE-2025-55179
No data.