Cyber Resilience

CVE-2025-55179

Whatsapp 2.25.8.14 – 2.25.23.83

Published
18 November 2025
Modified
25 November 2025
Patch / advisory
CVSS Score v3.1 5.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score 0.0017 6th percentile
Risk Priority 41 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2025-55179 is a medium-severity an unspecified weakness vulnerability in Whatsapp Whatsapp. Its CVSS base score is 5.4 (Medium).

Operationally, ranked at the 6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another…

more

user’s device. We have not seen evidence of exploitation in the wild.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-55177Same product: Whatsapp Whatsapp
CVE-2019-3568Same product: Whatsapp Whatsapp
CVE-2019-18426Same product: Whatsapp Whatsapp
CVE-2025-30401Same product: Whatsapp Whatsapp
CVE-2023-38538Same product: Whatsapp Whatsapp
CVE-2026-23863Same product: Whatsapp Whatsapp
CVE-2023-38537Same product: Whatsapp Whatsapp
CVE-2026-23866Same product: Whatsapp Whatsapp

Affected Assets

whatsapp
whatsapp
2.25.8.14 — 2.25.23.83 · 2.25.8.17 — 2.25.23.73
whatsapp
whatsapp business
2.25.8.14 — 2.25.23.82

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References