Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/CyberSecurity News/WhatsApp iOS Vulnerability Exposes Users to 0-Click Account Takeover
CyberSecurity News

WhatsApp iOS Vulnerability Exposes Users to 0-Click Account Takeover

Key Takeaways A sophisticated zero-click attack chain is enabling account takeovers of WhatsApp on iOS 16 devices. The attack exploits an Apple ImageIO vulnerability (CVE-2025-43300) and a WhatsApp...

Emy Elsamnoudy
Emy Elsamnoudy
May 27, 2026 3 Min Read
72 0

Key Takeaways

  • A sophisticated zero-click attack chain is enabling account takeovers of WhatsApp on iOS 16 devices.
  • The attack exploits an Apple ImageIO vulnerability (CVE-2025-43300) and a WhatsApp linked-device flaw (CVE-2025-55177).
  • Victims experience unauthorized messages, primarily financial requests, despite no visible suspicious activity in “Linked Devices.”
  • The attack allows adversaries to maintain a parallel WhatsApp session without user detection.
  • Updating iOS to the latest version is crucial for mitigation, as Apple has already patched one of the core vulnerabilities.

Unprecedented Zero-Click WhatsApp Hijack Targets iOS 16 Users

A disturbing new zero-click account takeover campaign is compromising WhatsApp accounts on iOS 16 devices, with numerous iPhone users reporting their accounts have been hijacked without any discernible interaction or warning. These incidents are particularly alarming as they occur silently, leaving no trace of linked devices visible to the legitimate user.

Table Of Content

  • Key Takeaways
  • Unprecedented Zero-Click WhatsApp Hijack Targets iOS 16 Users
  • Advanced Exploitation Bypasses Traditional Defenses
  • What You Should Do

Forenser, an Italian security firm, recently conducted a forensic investigation that unveiled the mechanics of this sophisticated attack. Threat actors are leveraging a zero-click exploit chain to gain surreptitious access to WhatsApp accounts, even while the rightful owner remains logged in and active.

Affected users, predominantly those with iPhones running iOS 16 – spanning models from the iPhone 8 to the iPhone 14 – have observed unauthorized messages being dispatched from their accounts, often soliciting money transfers. Critically, victims report finding no unusual entries within WhatsApp’s “Linked Devices” section, making detection exceedingly difficult.

Advanced Exploitation Bypasses Traditional Defenses

Unlike conventional WhatsApp hijacking methods, such as QR code phishing or GhostPairing campaigns, this newly identified attack vector requires no user interaction, rendering it significantly more perilous and challenging to identify. Forenser’s analysis of iOS unified logs revealed atypical “resync” events. These anomalies suggest that both the victim’s device and the attacker’s client were simultaneously vying for control over the same WhatsApp session.

This behavior indicates that the attacker establishes a clandestine, parallel session that is not registered as a linked device, thereby circumventing WhatsApp’s standard visibility and security protocols.

The attack chain reportedly leverages two critical vulnerabilities: CVE-2025-43300, an out-of-bounds write flaw within Apple’s ImageIO framework, and CVE-2025-55177, a WhatsApp linked-device synchronization vulnerability. The latter affects iOS versions prior to 16.7.12. CVE-2025-43300 facilitates malicious exploitation via specially crafted images, while CVE-2025-55177 pertains to the improper handling of WhatsApp linked-device synchronization messages on vulnerable iOS devices.

Researchers discovered that by chaining these flaws, attackers could extract cryptographic session data directly from the compromised device. This data then allows them to initialize a rogue WhatsApp client tethered to the victim’s account without triggering any security alerts. Supporting evidence includes recurring image-processing errors documented in system logs at the time of compromise, reinforcing the hypothesis of a malicious payload delivered through image-based vectors.

In controlled laboratory environments, Forenser successfully replicated portions of the attack. Their tests confirmed that session hijacking can indeed occur without the user’s knowledge and without leaving typical forensic indicators, such as new device pairings.

This campaign underscores a concerning trend: zero-click exploits, historically the domain of advanced state-sponsored actors, are increasingly being adopted by financially motivated cybercriminals. The widespread presence of unpatched iOS 16 devices, coupled with publicly documented vulnerabilities, has expanded the attack surface, enabling threat actors to scale sophisticated attacks more effectively.

What You Should Do

  • Update iOS Immediately: Ensure your iPhone is running the latest iOS version. Apple has already patched CVE-2025-43300 in newer releases, making this the most critical mitigation step.
  • Reinstall WhatsApp: As an additional protective measure, consider reinstalling WhatsApp. This action can help invalidate any existing attacker sessions.
  • Enable Chat Lock: Utilize WhatsApp’s chat lock feature to restrict unauthorized access to your conversations, adding an extra layer of security.
  • Re-authenticate Accounts: If you suspect compromise, re-authenticate your WhatsApp account on a clean, trusted device to force a new session and invalidate any rogue sessions.
  • Verify Financial Requests: Always independently verify any suspicious financial requests received via WhatsApp by contacting the sender through an alternative, trusted communication channel (e.g., a phone call). Do not rely solely on WhatsApp for verification, as attackers may intercept ongoing conversations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchphishingSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Open RDP Ports Exploited for Initial Access to Business Networks

Next Post

Glassworm Malware Abuses npm, PyPI, OpenVSX, GitHub to Target Developers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us