{"id":609048,"date":"2025-09-01T09:05:49","date_gmt":"2025-09-01T07:05:49","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=609048"},"modified":"2025-09-01T09:09:07","modified_gmt":"2025-09-01T07:09:07","slug":"whatsapp-patches-security-flaw-used-in-zero-day-attacks","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/609048-whatsapp-patches-security-flaw-used-in-zero-day-attacks.html","title":{"rendered":"WhatsApp patches security flaw used in zero-day attacks"},"content":{"rendered":"\n<p>Meta Platforms-owned WhatsApp has fixed a security vulnerability affecting its iOS and macOS messaging clients targeted in zero-day attacks.<\/p>\n\n\n\n<p>According to a company <a href=\"https:\/\/www.whatsapp.com\/security\/advisories\/2025\/\" data-type=\"link\" data-id=\"https:\/\/www.whatsapp.com\/security\/advisories\/2025\/\">statement<\/a>, the zero-click flaw impacted WhatsApp iOS clients before version 2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac V2.25.21.78.<\/p>\n\n\n\n<p>&#8220;Incomplete authorisation of linked device synchronisation messages for WhatsApp &#8230; could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target&#8217;s device,&#8221; it said.<\/p>\n\n\n\n<p>&#8220;We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms, may have been exploited in a sophisticated attack against specific targeted users.&#8221;<\/p>\n\n\n\n<p>Security Lab head at Amnesty International, Donncha \u00d3 Cearbhaill, <a href=\"https:\/\/x.com\/DonnchaC\/status\/1961444710620303653\" data-type=\"link\" data-id=\"https:\/\/x.com\/DonnchaC\/status\/1961444710620303653\">said<\/a> WhatsApp has only just warned some users that they had been targeted in an advanced spyware campaign in the past three months.<\/p>\n\n\n\n<p>&#8220;We&#8217;ve made changes to prevent this specific attack from occurring through WhatsApp,&#8221; it said in alerts sent to impacted users.<\/p>\n\n\n\n<p>&#8220;However, your device&#8217;s operating system could remain compromised by the malware or be targeted in other ways.&#8221;<\/p>\n\n\n\n<p>According to Cearbhaill, WhatsApp recommended that impacted users perform a factory reset on their devices to keep their operating systems and software up to date.<\/p>\n\n\n\n<p>The OS-level vulnerability on Apple platforms is being tracked as CVE-2025-43300, and the company released emergency updates earlier this month to patch the zero-day flaw.<\/p>\n\n\n\n<p>Bleeping Computer <a href=\"https:\/\/www.bleepingcomputer.com\/news\/apple\/apple-emergency-updates-fix-new-actively-exploited-zero-day\/\" data-type=\"link\" data-id=\"https:\/\/www.bleepingcomputer.com\/news\/apple\/apple-emergency-updates-fix-new-actively-exploited-zero-day\/\">reported<\/a> that the Apple flaw had been exploited in an &#8220;extremely sophisticated attack.&#8221;<\/p>\n\n\n\n<p>The vulnerability was caused by an out-of-bounds write weakness identified by Apple security researchers in the Image I\/O framework that enabled applications to read and write most image formats.<\/p>\n\n\n\n<p>Out-of-bounds writes result from malicious actors successfully exploiting vulnerabilities by supplying input to a program and causing it to write data outside the allocated memory buffer.<\/p>\n\n\n\n<p>This can lead to the program crashing, corrupting data, or enabling remote code execution.<\/p>\n\n\n\n<p>WhatsApp&#8217;s patching of this latest vulnerability comes after it fixed another zero-day flaw in March 2025. The flaw was exploited to install Paragon&#8217;s Graphite spyware.<\/p>\n\n\n\n<p>&#8220;WhatsApp has disrupted a spyware campaign by Paragon that targeted a number of users, including journalists and members of civil society,&#8221; a spokesperson told Bleeping Computer.<\/p>\n\n\n\n<p>&#8220;We&#8217;ve reached out directly to people who we believe were affected.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The vulnerability was used in an advanced spyware campaign targeting WhatsApp users on iOS and macOS.<\/p>\n","protected":false},"author":341076,"featured_media":606217,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[70936,605,101241,691,36626,74560,2594,48393],"class_list":["post-609048","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-amnesty-international","tag-apple","tag-donncha-o-cearbhaill","tag-ios","tag-macos","tag-meta-platforms-inc","tag-whatsapp","tag-whatsapp-business"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/609048"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=609048"}],"version-history":[{"count":3,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/609048\/revisions"}],"predecessor-version":[{"id":609066,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/609048\/revisions\/609066"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/606217"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=609048"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=609048"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=609048"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}