WhatsApp fixes ‘zero-click’ vulnerability that let hackers install spyware

WhatsApp fixes ‘zero-click’ vulnerability that let hackers install spyware

WhatsApp has confirmed the resolution of a significant security flaw in its application for iPhones and Macs, a vulnerability that allowed hackers to infiltrate the devices of targeted users using spyware. This information was disclosed in a security advisory issued earlier this week, where WhatsApp identified the vulnerability, designated as CVE-2025-43300, as potentially exploited in sophisticated attacks aimed at specific individuals. In conjunction with WhatsApp's announcement, Apple revealed last week that it had resolved a related issue, labeled CVE-2025-55177. Combined, these vulnerabilities posed a risk for certain Apple users, enabling attackers to extract data from their devices. Apple provided insights into the flaw, noting that processing a malicious image file could lead to memory corruption. They acknowledged awareness of reports suggesting that this vulnerability had been exploited in a highly advanced attack targeting specific individuals. Meta spokesperson Margarita Franklin informed TechCrunch that the company detected and remedied the vulnerability weeks prior and dispatched notifications to “less than 200” affected WhatsApp users. This flaw was present in WhatsApp versions for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78. Donncha Ó Cearbhaill, leader of Amnesty International’s Security Lab, characterized the recent attack as part of an “advanced spyware campaign” that has affected several users over the past three months. Cearbhaill noted that initial findings suggest the WhatsApp attack impacted both iPhone and Android users, including individuals from civil society. Zero-click vulnerabilities are particularly concerning as they allow attackers to exploit security flaws without requiring any action from the user, such as clicking a link or opening a file. This type of attack is deemed one of the most perilous forms of cybersecurity threats, as victims have limited means to defend themselves against such intrusions.

Sources : Mint

Published On : Aug 31, 2025, 04:20

Automotive
Tesla Expands Robotaxi Trials in Florida Ahead of Earnings Report

Tesla has introduced an undisclosed number of its self-driving Model Y SUVs in Orlando and Tampa, just a day prior to it...

TechCrunch | Jul 21, 2026, 18:45
Tesla Expands Robotaxi Trials in Florida Ahead of Earnings Report
AI
U.S. Considers Sanctions on Chinese AI Firms Amid IP Concerns

In a significant move, U.S. Treasury Secretary Scott Bessent announced on Tuesday that the United States is set to scrut...

TechCrunch | Jul 21, 2026, 15:45
U.S. Considers Sanctions on Chinese AI Firms Amid IP Concerns
Computing
Nvidia Unveils Vera CPU: A Bold Move to Disrupt the AI Server Market

Nvidia is making headlines once again, not just as a leader in graphics processing units (GPUs) but as a contender in th...

CNBC | Jul 21, 2026, 15:20
Nvidia Unveils Vera CPU: A Bold Move to Disrupt the AI Server Market
AI
AI Giants Ramp Up Lobbying Efforts as Tech Spending Shifts

OpenAI and Anthropic have significantly escalated their federal lobbying investments, marking a record high in the secon...

CNBC | Jul 21, 2026, 16:45
AI Giants Ramp Up Lobbying Efforts as Tech Spending Shifts
Automotive
Einride Expands Electric Trucking Vision with $38M Flipturn Acquisition

Swedish company Einride, known for its electric and autonomous trucking solutions, has made a significant move by acquir...

TechCrunch | Jul 21, 2026, 19:25
Einride Expands Electric Trucking Vision with $38M Flipturn Acquisition
View All News