WhatsApp iOS Vulnerability Exposes Users to 0-Click Account Takeover
Key Takeaways A sophisticated zero-click attack chain is enabling account takeovers of WhatsApp on iOS 16 devices. The attack exploits an Apple ImageIO vulnerability (CVE-2025-43300) and a WhatsApp...
Key Takeaways
- A sophisticated zero-click attack chain is enabling account takeovers of WhatsApp on iOS 16 devices.
- The attack exploits an Apple ImageIO vulnerability (CVE-2025-43300) and a WhatsApp linked-device flaw (CVE-2025-55177).
- Victims experience unauthorized messages, primarily financial requests, despite no visible suspicious activity in “Linked Devices.”
- The attack allows adversaries to maintain a parallel WhatsApp session without user detection.
- Updating iOS to the latest version is crucial for mitigation, as Apple has already patched one of the core vulnerabilities.
Unprecedented Zero-Click WhatsApp Hijack Targets iOS 16 Users
A disturbing new zero-click account takeover campaign is compromising WhatsApp accounts on iOS 16 devices, with numerous iPhone users reporting their accounts have been hijacked without any discernible interaction or warning. These incidents are particularly alarming as they occur silently, leaving no trace of linked devices visible to the legitimate user.
Table Of Content
Forenser, an Italian security firm, recently conducted a forensic investigation that unveiled the mechanics of this sophisticated attack. Threat actors are leveraging a zero-click exploit chain to gain surreptitious access to WhatsApp accounts, even while the rightful owner remains logged in and active.
Affected users, predominantly those with iPhones running iOS 16 – spanning models from the iPhone 8 to the iPhone 14 – have observed unauthorized messages being dispatched from their accounts, often soliciting money transfers. Critically, victims report finding no unusual entries within WhatsApp’s “Linked Devices” section, making detection exceedingly difficult.
Advanced Exploitation Bypasses Traditional Defenses
Unlike conventional WhatsApp hijacking methods, such as QR code phishing or GhostPairing campaigns, this newly identified attack vector requires no user interaction, rendering it significantly more perilous and challenging to identify. Forenser’s analysis of iOS unified logs revealed atypical “resync” events. These anomalies suggest that both the victim’s device and the attacker’s client were simultaneously vying for control over the same WhatsApp session.
This behavior indicates that the attacker establishes a clandestine, parallel session that is not registered as a linked device, thereby circumventing WhatsApp’s standard visibility and security protocols.
The attack chain reportedly leverages two critical vulnerabilities: CVE-2025-43300, an out-of-bounds write flaw within Apple’s ImageIO framework, and CVE-2025-55177, a WhatsApp linked-device synchronization vulnerability. The latter affects iOS versions prior to 16.7.12. CVE-2025-43300 facilitates malicious exploitation via specially crafted images, while CVE-2025-55177 pertains to the improper handling of WhatsApp linked-device synchronization messages on vulnerable iOS devices.
Researchers discovered that by chaining these flaws, attackers could extract cryptographic session data directly from the compromised device. This data then allows them to initialize a rogue WhatsApp client tethered to the victim’s account without triggering any security alerts. Supporting evidence includes recurring image-processing errors documented in system logs at the time of compromise, reinforcing the hypothesis of a malicious payload delivered through image-based vectors.
In controlled laboratory environments, Forenser successfully replicated portions of the attack. Their tests confirmed that session hijacking can indeed occur without the user’s knowledge and without leaving typical forensic indicators, such as new device pairings.
This campaign underscores a concerning trend: zero-click exploits, historically the domain of advanced state-sponsored actors, are increasingly being adopted by financially motivated cybercriminals. The widespread presence of unpatched iOS 16 devices, coupled with publicly documented vulnerabilities, has expanded the attack surface, enabling threat actors to scale sophisticated attacks more effectively.
What You Should Do
- Update iOS Immediately: Ensure your iPhone is running the latest iOS version. Apple has already patched CVE-2025-43300 in newer releases, making this the most critical mitigation step.
- Reinstall WhatsApp: As an additional protective measure, consider reinstalling WhatsApp. This action can help invalidate any existing attacker sessions.
- Enable Chat Lock: Utilize WhatsApp’s chat lock feature to restrict unauthorized access to your conversations, adding an extra layer of security.
- Re-authenticate Accounts: If you suspect compromise, re-authenticate your WhatsApp account on a clean, trusted device to force a new session and invalidate any rogue sessions.
- Verify Financial Requests: Always independently verify any suspicious financial requests received via WhatsApp by contacting the sender through an alternative, trusted communication channel (e.g., a phone call). Do not rely solely on WhatsApp for verification, as attackers may intercept ongoing conversations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.