Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

Posted on August 29, 2025August 29, 2025 By CWS

A complicated assault marketing campaign has leveraged a beforehand unknown zero-day vulnerability in WhatsApp on Apple units to focus on particular customers, the corporate has confirmed.

The vulnerability, now recognized as CVE-2025-55177, was mixed with a separate vulnerability in Apple’s working techniques to compromise units and entry consumer knowledge.

WhatsApp has since patched the vulnerability and has been sending risk notifications to people it believes had been focused by the superior spy ware marketing campaign inside the final 90 days. The corporate is urging affected customers to take fast motion to safe their units.

A Two-Pronged Assault

The assault exploited a sequence of vulnerabilities to realize entry to focus on units. The preliminary entry level was by way of WhatsApp on iOS and macOS.

The WhatsApp Vulnerability (CVE-2025-55177): This vulnerability existed in the best way WhatsApp dealt with linked system synchronization messages. In response to a safety advisory from WhatsApp, the flaw might permit an attacker to set off the processing of content material from an arbitrary URL on a goal’s system.

This affected WhatsApp for iOS variations earlier than v2.25.21.73, WhatsApp Enterprise for iOS earlier than v2.25.21.78, and WhatsApp for Mac earlier than v2.25.21.78.

ProductAffected VersionsWhatsApp for iOSVersions previous to v2.25.21.73WhatsApp Enterprise for iOSVersions previous to v2.25.21.78WhatsApp for MacVersions previous to v2.25.21.78

The Apple OS Vulnerability (CVE-2025-43300): This WhatsApp vulnerability was used along side a zero-day flaw inside Apple’s iOS, iPadOS, and macOS. Tracked as CVE-2025-43300, this bug was an out-of-bounds write subject within the ImageIO framework.

Apple acknowledged that processing a malicious picture file might result in reminiscence corruption, and confirmed that the difficulty “could have been exploited in a particularly refined assault towards particular focused people”. The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has added this vulnerability to its catalog of recognized exploited threats.

WhatsApp’s Response

Inner researchers on the WhatsApp Safety Workforce found the vulnerability. In response, the corporate has deployed a patch to stop the assault from occurring by way of its platform.

Notifications despatched to focused customers warned {that a} malicious message could have been used to compromise their system and the information it accommodates, together with messages.

In a message to affected customers, the corporate acknowledged, “We’ve made modifications to stop this particular assault from occurring by way of WhatsApp. Nonetheless, your system’s working system might stay compromised by the malware or be focused in different methods.”

Notification to Customers

Because of the refined nature of the spy ware, WhatsApp is recommending that focused people carry out a full system manufacturing facility reset.

The corporate additionally strongly urges all customers to maintain their units up to date to the most recent model of their working system and to make sure their WhatsApp utility is updated.

Notification to Customers

This incident is the most recent instance of mercenary spy ware campaigns focusing on high-profile people, together with journalists and civil society members, by way of well-liked communication platforms.

Discover this Story Fascinating! Observe us on LinkedIn and X to Get Extra Immediate Updates.

Cyber Security News Tags:0Day, Exploited, Hack, IOS, Mac, Users, Vulnerability, WhatsApp

Post navigation

Previous Post: Citrix Netscaler 0-day RCE Vulnerability Patched
Next Post: Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution

Related Posts

BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware Cyber Security News
EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections Cyber Security News
ScarCruft Exploits Cloud Services in New Malware Campaign ScarCruft Exploits Cloud Services in New Malware Campaign Cyber Security News
Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Cyber Security News
Nissan Confirms Data Breach Following Unauthorized Access to Red Hat Servers Nissan Confirms Data Breach Following Unauthorized Access to Red Hat Servers Cyber Security News
OpenAI Launches  ChatGPT Go Plan with Unlimited Access to GPT-5 OpenAI Launches $4 ChatGPT Go Plan with Unlimited Access to GPT-5 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News