Exploited Vulnerabilities Daily
🌐 English

Home › Meta Platforms

CVE-2025-55177: Meta Platforms WhatsApp

EPSS4.7%No. 1427 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV3
Same product3
FieldValue
VendorMeta Platforms
ProductWhatsApp
NameMeta Platforms WhatsApp Incorrect Authorization Vulnerability
Added to KEV2025-09-02
US federal due date2025-09-23
Ransomware useUnknown
CWECWE-863

CISA description

Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2019-18426Meta Platforms WhatsApp2022-05-2367.8%Unknown
CVE-2019-3568Meta Platforms WhatsApp2022-04-1930.0%Unknown

NVD — CVE-2025-55177

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Meta Platforms WhatsApp vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-02.