WhatsApp fixed a zero-click bug in its iOS and Mac apps that was being used, alongside a now-fixed Apple flaw, to hack into devices of “specific targeted users”
“Incomplete authorization of linked device synchronization messages … Matt Suiche : New WhatsApp advisory (CVE-2025-55177) just came out. Amnesty International says they have been investigating cases. … Bluesky: Matthew Green / @matthewdgreen : This is a week of bad Apple vulns. This one hardware. github.com/JGoyd/A16-Fu... Mastodon: @techlore@social.lol : This isn't WhatsApp's first rodeo with spyware. Remember: — • 2019: NSO Group's Pegasus infected 1,400+ users (NSO just paid $167M in damages) — • Earlier this year: 90 Italian users targeted with Paragon spyware — Key takeaways for our community: — ✅ Enable lockdown mode + use Signal … Forums: r/apple : WhatsApp fixes ‘zero-click’ bug used to hack Apple users with spyware BeauHD / Slashdot : WhatsApp Fixes ‘Zero-Click’ Bug Used To Hack Apple Users With Spyware
Context & Ripple Effects
This is the latest in a recurring pattern of WhatsApp flaws being paired with sophisticated surveillance activity: a 2019 WhatsApp call-function flaw was tied to NSO Group spyware, and WhatsApp said it disrupted a campaign targeting journalists and civil-society members earlier this year. The new case matters because the reported exploit chain crossed WhatsApp and Apple software, while Amnesty International is investigating affected cases.
First-order effects
- WhatsApp’s iOS and Mac users need the vendor’s fix for CVE-2025-55177, while Apple’s separate patch closes the companion weakness used in the reported device-compromise chain.
- The fixes cut off a reported zero-click route used against specifically selected users, rather than requiring them to interact with a malicious call or message.
Second-order effects
- The case puts renewed pressure on messaging and platform security teams to assess linked-device synchronization and cross-product exploit paths, not just isolated app vulnerabilities.
- For investigators and at-risk groups, the paired patches may narrow the window for confirming incidents; Amnesty International’s ongoing casework becomes an important source of visibility into who was targeted and how.
Third-order effects
- If targeted spyware operations continue to combine flaws across apps and operating systems, security assurance will increasingly depend on coordinated patching and incident disclosure across vendors.
- The recurring presence of WhatsApp in reported spyware cases may sustain scrutiny of commercial surveillance tools and of the safeguards available to journalists, activists, and other high-risk users.
The trend: This is another data point in the shift from single-product vulnerabilities toward targeted spyware chains that span messaging apps and device platforms.