WhatsApp has fixed a security bug in its iOS and Mac apps that was used to hack into the devices of specific targeted users. The vulnerability, known as CVE-2025-55177, was used alongside another flaw in iOS and Macs, which Apple fixed last week as CVE-2025-43300.
An advanced spyware campaign targeted WhatsApp users over the past 90 days, described as a “zero-click” attack that does not require any interaction from the victim. The bugs allowed attackers to steal data from Apple devices through WhatsApp.
The attack compromised devices and data, including messages, but it’s unclear who is behind it. Meta confirmed they patched the flaw and notified less than 200 affected users.
This is not the first time WhatsApp users have been targeted by government spyware, with NSO Group ordered to pay damages for a 2019 hacking campaign. Earlier this year, a spyware campaign targeted 90 users in Italy, involving members of civil society and journalists.
