boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-55177

Facebook WhatsApp Desktop for Mac — Meta Platforms WhatsApp
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  L  N    5.4   .0430   90.8   YES
AFFECTED
  Product                    Versions     Fixed
  WhatsApp Desktop for Mac   2.22.25.2 –  —
  WhatsApp Business for iOS  2.22.25.2 –  —
  WhatsApp for iOS           2.22.25.2 –  —
TIMELINE
  Aug 8   Reserved by facebook
  Aug 29  Published (CNA: facebook)
  Sep 2   Added to CISA KEV, remediation due 2025-09-23
CNA: facebook · CVSS v3.1 · 3 references · KEV due September 23, 2025

Description

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 8, 2025ReservedReserved by facebook
August 29, 2025PublishedPublished (CNA: facebook)
September 2, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-09-23

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
FacebookWhatsApp Desktop for Mac—2.22.25.2—
FacebookWhatsApp Business for iOS—2.22.25.2—
FacebookWhatsApp for iOS—2.22.25.2—

References (3)

Related

Authoritative record: CVE-2025-55177 at cve.org

Vendors: facebook

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-55177 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.