/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

WhatsApp fixed a zero-click bug in its iOS and Mac apps that was being used, alongside a now-fixed Apple flaw, to hack into devices of “specific targeted users”

“Incomplete authorization of linked device synchronization messages … Matt Suiche : New WhatsApp advisory (CVE-2025-55177) just came out.  Amnesty International says they have been investigating cases. … Bluesky: Matthew Green / @matthewdgreen : This is a week of bad Apple vulns.  This one hardware. github.com/JGoyd/A16-Fu... Mastodon: @techlore@social.lol : This isn't WhatsApp's first rodeo with spyware.  Remember:  —  • 2019: NSO Group's Pegasus infected 1,400+ users (NSO just paid $167M in damages)  —  • Earlier this year: 90 Italian users targeted with Paragon spyware  —  Key takeaways for our community:  —  ✅ Enable lockdown mode + use Signal … Forums: r/apple : WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware BeauHD / Slashdot : WhatsApp Fixes ‘Zero-Click’ Bug Used To Hack Apple Users With Spyware

TechCrunch Zack Whittaker

Context & Ripple Effects

This is the latest in a recurring pattern of WhatsApp flaws being paired with sophisticated surveillance activity: a 2019 WhatsApp call-function flaw was tied to NSO Group spyware, and WhatsApp said it disrupted a campaign targeting journalists and civil-society members earlier this year. The new case matters because the reported exploit chain crossed WhatsApp and Apple software, while Amnesty International is investigating affected cases.

First-order effects

  • WhatsApp’s iOS and Mac users need the vendor’s fix for CVE-2025-55177, while Apple’s separate patch closes the companion weakness used in the reported device-compromise chain.
  • The fixes cut off a reported zero-click route used against specifically selected users, rather than requiring them to interact with a malicious call or message.

Second-order effects

  • The case puts renewed pressure on messaging and platform security teams to assess linked-device synchronization and cross-product exploit paths, not just isolated app vulnerabilities.
  • For investigators and at-risk groups, the paired patches may narrow the window for confirming incidents; Amnesty International’s ongoing casework becomes an important source of visibility into who was targeted and how.

Third-order effects

  • If targeted spyware operations continue to combine flaws across apps and operating systems, security assurance will increasingly depend on coordinated patching and incident disclosure across vendors.
  • The recurring presence of WhatsApp in reported spyware cases may sustain scrutiny of commercial surveillance tools and of the safeguards available to journalists, activists, and other high-risk users.

The trend: This is another data point in the shift from single-product vulnerabilities toward targeted spyware chains that span messaging apps and device platforms.

Discussion

  • @donnchac Donncha Ó Cearbhaill on x
    🚨 BREAKING: New zero-click exploit used to hack WhatsApp users. WhatsApp has just sent out a round of threat notifications to individuals they believe where targeted by an advanced spyware campaign in past 90 days. Seek out expert help if you have received this alert [image]
  • @patrickwardle Patrick Wardle on x
    Maybe we should all be taking closer looks at our iOS/macOS WhatsApp crash reports!? 😬 (TBD if related to CVE-2025-55117) [image]
  • @jsrailton John Scott-Railton on x
    @WhatsApp 4/Here's the Apple CVE. If you've been doing your @apple & @whatsapp updates lately, you are protected from this. Somewhere, earlier this summer, some people in a room probably had a pretty bad day when this clever cross-app chain stopped working. Which is good. [image]
  • @jsrailton John Scott-Railton on x
    @WhatsApp 3/ The regular tempo of large platforms catching sophisticated exploits is a good sign. They're paying attention & devoting resources to this growing category of highly targeted, sophisticated attacks. But it's also a reminder of the magnitude of the threat out there...
  • @donnchac Donncha Ó Cearbhaill on x
    Early indications are that the WhatsApp attack is impacting both iPhone and Android users, civil society individuals among them. Government spyware continues to pose a threat to journalists and human rights defenders. Kudos to WhatsApp and Apple for catching it and notifying
  • @donnchac Donncha Ó Cearbhaill on x
    Also important: the Apple vulnerability was in a core image library, targeting possible through other apps besides WhatsApp. Make sure to update your devices and enabled iOS Lockdown Mode or Android's Advanced Protection Mode to help protect against attacks like this
  • @jsrailton John Scott-Railton on x
    NEW: @WhatsApp caught & fixed a sophisticated zero click attack... Now they've published an advisory about it. Say attackers combined the exploit with an @Apple vulnerability to hack a specific group of targets (i.e. this wasn't pointed at everybody) Quick thoughts 1/ [image]
  • @matthewdgreen Matthew Green on bluesky
    This is a week of bad Apple vulns.  This one hardware. github.com/JGoyd/A16-Fu...
  • r/apple r on reddit
    WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware