Zero-click attack hijacks WhatsApp accounts on iOS 16
Overview
A new zero-click attack has been discovered that targets WhatsApp accounts on devices running iOS 16. This attack takes advantage of vulnerabilities in the ImageIO framework, specifically identified as CVE-2025-43300, and potentially CVE-2025-55177. By exploiting these flaws, attackers can gain unauthorized access to WhatsApp sessions without any user interaction. This is particularly concerning for users of iOS 16, as it opens the door for unauthorized access to private messages and data. Users should remain vigilant and consider updating their devices as soon as patches are available to mitigate this risk.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: WhatsApp on iOS 16 (specifically affected versions using ImageIO framework vulnerabilities CVE-2025-43300 and CVE-2025-55177)
- Action Required: Users are advised to update their iOS devices to the latest version as soon as patches are released.
- Timeline: Newly disclosed
Original Article Summary
The attack exploits vulnerabilities in iOS 16, specifically CVE-2025-43300 within the ImageIO framework and potentially CVE-2025-55177, to gain unauthorized access to WhatsApp sessions.
Impact
WhatsApp on iOS 16 (specifically affected versions using ImageIO framework vulnerabilities CVE-2025-43300 and CVE-2025-55177)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users are advised to update their iOS devices to the latest version as soon as patches are released. Regularly check for updates to ensure vulnerabilities are addressed.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to iOS, CVE, Apple.