Targeted spyware chain across WhatsApp and Apple Image I/O
Case score 56
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 56
- Main story score
- 56
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 1
- Campaign Defines the targeted spyware activity and the chained use of WhatsApp and Apple vulnerabilities. main
- Vulnerability Provides the WhatsApp zero-click flaw, affected versions, and victim-handling guidance that frame the chain. context
Overview
Latest development Open development history Apple patches CVE-2025-43300 on newer iPhone, iPad, and Mac releases Apple patched CVE-2025-43300 on August 20, 2025 for iOS 18.6.2, iPadOS 18.6.2, iPadOS 17.7.10, and macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8, addressing an Image I/O out-of-bounds write that could let a malicious image file cause memory corruption.
-
WhatsApp users are warned about a targeted spyware campaign chaining CVE-2025-55177 and CVE-2025-43300
Apple backported CVE-2025-43300 fixes to older iPhones and iPads running iOS 15.8.5 / 16.7.12 and iPadOS 15.8.5 / 16.7.12, and WhatsApp users were warned that their devices were targeted in an advanced spyware campaign that chained CVE-2025-55177 with Apple's zero-day against specific targeted individuals.
-
WhatsApp patches CVE-2025-55177 in iOS and Mac clients
WhatsApp patched CVE-2025-55177 in WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac after assessing that incomplete authorization of linked device synchronization messages could let an unrelated user trigger processing of content from an arbitrary URL on a target's device. The company said the zero-click flaw may have been exploited with CVE-2025-43300 on Apple platforms in targeted attacks against specific users, and it advised potentially impacted users to factory reset devices and keep their operating system and software up to date.