Vulnerability Description
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| >= 2.25.8.14, < 2.25.23.83 | ||
| Whatsapp Business | >= 2.25.8.14, < 2.25.23.82 |
References
- https://www.facebook.com/security/advisories/cve-2025-55179Vendor Advisory
- https://www.whatsapp.com/security/advisories/2025/Vendor Advisory
FAQ
What is CVE-2025-55179?
CVE-2025-55179 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger p...
How severe is CVE-2025-55179?
CVE-2025-55179 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55179?
Check the references section above for vendor advisories and patch information. Affected products include: Whatsapp Whatsapp, Whatsapp Whatsapp Business.