WhatsApp has patched a serious vulnerability in its iOS and Mac clients that attackers used alongside an Apple operating system flaw to quietly compromise targeted users. WhatsApp tracks the messaging app issue as CVE 2025 55177 and says the flaw could have allowed content from an outside URL to be processed on a target device.
Apple previously fixed a separate vulnerability in its ImageIO code that it tracked as CVE 2025 43300. Apple said that that flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals and it released security updates to close the problem. The two bugs were chained together in the attacks.

What happened
Security researchers and watchdog groups described the campaign as a zero click attack. That term means that the exploit required no action from the victim to trigger. Amnesty International Security Lab noted that the operation was an advanced spyware campaign and that investigators began seeing activity in recent months. Meta said it issued fewer than two hundred breach notifications to affected users.
The combined exploit delivered code to a target device that could steal data and messages. WhatsApp explained that an unrelated account could trigger processing of content from an arbitrary URL on a target device when both flaws were present. That process allowed attackers to use WhatsApp as a delivery channel and to exploit a separate Apple bug to run malicious code.
What to do
Latest version of WhatsApp iPhones and Macs have the latest patches to prevent these attacks, so update now to the fixed versions of the WhatsApp app in WhatsApp security advisories. Apple security updates with CVE 2025 43300 should also be installed by Apple users. Both the operating system and messaging app should be updated, which seals the chain with which attackers acted.

In case you got a security notice at WhatsApp heed the instructions in the notice. High risk accounts might be recommended to take further actions by security teams and investigators like changing the authentication settings and reviewing the device linkings. The organizations that sponsor activists journalists or civil society groups must take risk and implement greater protections.
Security researchers are still investigating who created the spyware and which vendor may have supplied it. Attribution can be difficult in these cases. WhatsApp and outside investigators have not publicly named a specific spyware maker tied to this campaign. Past cases establish that commercial surveillance tools have been used in attacks on messaging apps.