Answer in brief
CVE-2025-55177 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Facebook/WhatsApp Business for iOS (generic), Facebook/WhatsApp Desktop for Mac (generic), Facebook/WhatsApp for iOS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Facebook/WhatsApp Business for iOS (generic), Facebook/WhatsApp Desktop for Mac (generic), Facebook/WhatsApp for iOS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Facebook/WhatsApp Business for iOSgeneric | >=2.22.25.2 <2.25.21.78 | 2.25.21.78 |
| Facebook/WhatsApp Desktop for Macgeneric | >=2.22.25.2 <2.25.21.78 | 2.25.21.78 |
| Facebook/WhatsApp for iOSgeneric | >=2.22.25.2 <2.25.21.73 | 2.25.21.73 |
Published upstream
Aug 29, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Feb 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 2, 2025
Evidence: source:kev:kev:kev:recordIncomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-55177 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Facebook/WhatsApp Business for iOS (generic), Facebook/WhatsApp Desktop for Mac (generic), Facebook/WhatsApp for iOS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Facebook/WhatsApp Business for iOS (generic), Facebook/WhatsApp Desktop for Mac (generic), Facebook/WhatsApp for iOS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Facebook/WhatsApp Business for iOSgeneric | >=2.22.25.2 <2.25.21.78 | 2.25.21.78 |
| Facebook/WhatsApp Desktop for Macgeneric | >=2.22.25.2 <2.25.21.78 | 2.25.21.78 |
| Facebook/WhatsApp for iOSgeneric | >=2.22.25.2 <2.25.21.73 | 2.25.21.73 |
Published upstream
Aug 29, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Feb 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 2, 2025
Evidence: source:kev:kev:kev:recordIncomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
Quoted source text, attributed separately from HOL analysis.