CVE-2025-55177

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 6 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.76%
probability
This CVE has a 0.76% probability of being exploited in the next 30 days.
0% Top 73.6th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Incomplete authorization of linked device synchronization messages

Attack Intelligence

Google Project Zero

Patched
Aug. 20, 2025
Reported by
Internal Researchers on the WhatsApp Security Team
Root Cause Analysis
???

Signal Intelligence

Confidence
85%
EPSS 0.76%
Mentions 6
Last Seen Sep 16, 2025

CNA Information

Analyst Note

CVE-2025-55177 is confirmed as a legitimate vulnerability affecting WhatsApp across multiple platforms, with demonstrated exploitation in the wild and patches released by vendors. The vulnerability involves incomplete authorization in linked device synchronization that could enable unauthorized content processing, corroborated by reporting from reputable security sources and Google Project Zero involvement.

Threat Actors 10

Hacking Team
apt_group 🇮🇹 IT
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Watchdog
apt_group 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
[Unnamed group]
apt_group 🇨🇳 CN
Stealth Falcon
apt_group Information theft and espionage 🇦🇪 AE
Pat Bear
apt_group 🇸🇾 SY
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Lurk
apt_group Financial crime 🇷🇺 RU

Triage Info

Decided atMar 03, 2026