Hackers Chained Apple and WhatsApp Flaws in Spyware Campaign
Meta patched a WhatsApp zero-click flaw exploited in targeted attacks on Apple devices, notifying fewer than 200 users during a 90-day advanced spyware campaign, experts said.
- On August 29, 2025, WhatsApp patched CVE-2025-55177 exploited in targeted zero-day attacks on iOS and macOS, sending threat notifications to people it believes were targeted.
- WhatsApp's Friday security advisory said the flaw stemmed from incomplete authorization of linked device synchronization messages, chained with Apple ImageIO out-of-bounds write .
- The flaw enabled a zero-click attack that compromised iPhones and Macs without user interaction, and WhatsApp advised a full device factory reset plus updating to latest WhatsApp and OS versions.
- Meta confirmed it sent fewer than 200 notifications to users it believes were affected, linking earlier campaigns to targeting journalists and civil society, including around 90 users in Italy and legal cases against spyware vendors.
- Experts say the patch underscores the need for proactive vulnerability hunting, international collaboration on cyber threats, and user vigilance to curb spyware proliferation.
26 Articles
26 Articles
WhatsApp fixes iPhone and Mac bug used in zero-click spyware attack on Apple users
WhatsApp has patched a security flaw exploited in a sophisticated spyware attack targeting Apple users. The vulnerability, part of a zero-click attack, compromised data on the devices of specific users.
Meta has corrected critical vulnerabilities on WhatsApp that allowed attacks without user interaction, both on iPhones and Macs, compromising data for at least three months.


WhatsApp flaw paired with iOS 18 exploit delivered zero-click spyware
A new spyware campaign chained WhatsApp and a flaw in iOS 18.6 to expose users to a "zero-click" hack that required no interaction to compromise an iPhone.WhatsApp on an iPhoneMeta confirmed on August 29, 2025, that it had patched a flaw in its iOS and Mac apps. The flaw was tracked as CVE-2025-55177 in the database of known security flaws.Apple had previously issued a fix for a related iOS and macOS vulnerability, CVE-2025-43300 on August 20. T…
Hackers chained Apple and WhatsApp flaws in spyware campaign
A few days ago, Apple fixed a vulnerability on iOS and macOS that “may have been exploited in an extremely sophisticated attack against specific targeted individuals.” Now, new details have emerged, and it appears that the hacking campaign also leveraged a now-fixed WhatsApp flaw to target its victims. Here are the details. more…
Coverage Details
Bias Distribution
- 71% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium