Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Sep 23, 2025

CVE-2025-55177

High
EPSS 0.9%CISA KEV

Description

Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.

EPSS — Exploit Probability

0.9%

Higher than 76.1% of all CVEs

Required Action

https://www.whatsapp.com/security/advisories/2025/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-55177

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
0.9%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Sep 2, 2025

Added to KEV

Sep 2, 2025

Remediation Due

Sep 23, 2025

Affected Product

Meta Platforms

WhatsApp

View all Meta Platforms CVEs