Experts at DarkNavyOrg have discovered a dangerous vulnerability in the WhatsApp messenger (owned by Meta Platforms Inc., designated an extremist organization in Russia), which allows hackers to remotely execute code on Apple devices. The attack requires no action from the victim, making it especially insidious, SecurityLab reports.
The problem is linked to two flaws:
In a demonstration, researchers sent an infected photo to a target number and silently hacked the device. This allows attackers to:
The danger lies in the fact that the victim does not need to open the photo or interact with the message — infection happens automatically.
The vulnerability affects devices running iOS, iPadOS, and macOS where WhatsApp is installed. The exact number of potential victims is unknown, but with billions of users, the threat is massive.
While WhatsApp and Apple are preparing fixes, users can:
Patches are expected in upcoming WhatsApp and Apple OS updates.
The flaw highlights risks even in protected ecosystems like iOS. The fact that no user interaction is needed makes the attack invisible, while potential access to personal data threatens privacy. It’s a reminder of the importance of timely updates and vigilance in the digital world.
Critical vulnerabilities CVE-2025-55177 and CVE-2025-43300 allow hackers to compromise Apple devices through WhatsApp by sending a malicious photo. Users are strongly advised to update both the app and their operating system. Apple and WhatsApp are preparing patches, but vigilance remains the key to safety.
month
week
day