Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Vulnerability

Targeted spyware chain across WhatsApp and Apple Image I/O

Updated 16.09.2025 15:16
Case score 56
Members 2 First seen 29.08.2025 19:31 Latest activity 16.09.2025 15:16

Overview

Targeted spyware activity used a **WhatsApp** zero-click flaw and an **Apple** Image I/O vulnerability to reach specific users with a silent delivery path. WhatsApp tied **CVE-2025-55177** to **CVE-2025-43300** in targeted zero-day attacks, and Apple already had emergency fixes in place for the platform flaw. WhatsApp sent threat notifications and told potentially impacted users to factory reset devices and keep software current. Available evidence confirms patching and warning activity, but not the exact operator identity or the full number of affected devices.
Latest development Open development history 2 earlier developments Apple patches CVE-2025-43300 on newer iPhone, iPad, and Mac releases Apple patched CVE-2025-43300 on August 20, 2025 for iOS 18.6.2, iPadOS 18.6.2, iPadOS 17.7.10, and macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8, addressing an Image I/O out-of-bounds write that could let a malicious image file cause memory corruption.
  1. Earlier development

    WhatsApp users are warned about a targeted spyware campaign chaining CVE-2025-55177 and CVE-2025-43300

    Apple backported CVE-2025-43300 fixes to older iPhones and iPads running iOS 15.8.5 / 16.7.12 and iPadOS 15.8.5 / 16.7.12, and WhatsApp users were warned that their devices were targeted in an advanced spyware campaign that chained CVE-2025-55177 with Apple's zero-day against specific targeted individuals.

  2. Earlier development

    WhatsApp patches CVE-2025-55177 in iOS and Mac clients

    WhatsApp patched CVE-2025-55177 in WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac after assessing that incomplete authorization of linked device synchronization messages could let an unrelated user trigger processing of content from an arbitrary URL on a target's device. The company said the zero-click flaw may have been exploited with CVE-2025-43300 on Apple platforms in targeted attacks against specific users, and it advised potentially impacted users to factory reset devices and keep their operating system and software up to date.

Signals

Impact signals
Exploitation
CVEs/products
Remediation
Status

Threat actor context

1 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Campaign WhatsApp spyware campaign chaining CVE-2025-55177 and CVE-2025-43300
Updated 16.09.2025 15:16 Lead Contribution 56
Objective Espionage Campaign Active Patch Patch Available

A **targeted spyware campaign** hit **specific WhatsApp users**, increasing the risk of covert device surveillance. The operation chained **CVE-2025-55177** in WhatsApp with **CVE-2025-43300** in Apple software, making the attack path more effective against high-value devices. The activity was described as **extremely sophisticated** and focused on a **limited cohort** rather than broad consumer targeting. The timeframe points to **late August to September 2025**, and the same exploit chain was later linked to attacks against **Samsung Android devices**.

Vulnerability WhatsApp iOS and Mac zero-click authorization exploited in zero-day attacks security flaw (multiple vulnerabilities)
Updated 29.08.2025 19:31 Context
Exploitation Active Exploitation CVSS 8.0 High Patch Patch Available

**WhatsApp** patched **CVE-2025-55177**, a **zero-click authorization flaw** in its **iOS and Mac clients** that was exploited in **targeted zero-day attacks**. The bug could let an unrelated user trigger processing of content from an **arbitrary URL** on a target device. Affected versions include **WhatsApp for iOS prior to 2.25.21.73**, **WhatsApp Business for iOS v2.25.21.78**, and **WhatsApp for Mac v2.25.21.78**. WhatsApp tied the flaw to **incomplete authorization of linked device synchronization messages** and said it may have been used with **CVE-2025-43300** on Apple platforms.