WhatsApp recently patched a critical security flaw (CVE-2025-55177) in its iOS and Mac apps that allowed a zero-click spyware attack. This vulnerability, combined with an Apple flaw (CVE-2025-43300), enabled attackers to steal data from targeted users' devices without their interaction. Amnesty International's Security Lab described the attack as sophisticated, affecting users over the past three months. WhatsApp sent notifications to fewer than 200 affected users. While the attacker remains unidentified, this isn't the first time WhatsApp users have been targeted by government spyware.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments