Moneycontrol PRO
HomeTechnologyNew WhatsApp flaw allows hackers to bypass authorisation and steal personal data, warns government: Tips to secure your account

New WhatsApp flaw allows hackers to bypass authorisation and steal personal data, warns government: Tips to secure your account

India’s cybersecurity watchdog, CERT-In, has issued a high-severity warning about a newly discovered authorization bypass vulnerability in WhatsApp. The flaw, tracked as CVE-2025-55177.

September 01, 2025 / 18:12 IST
whatsapp

India’s cybersecurity watchdog, CERT-In, has issued a high-severity warning about a newly discovered authorization bypass vulnerability in WhatsApp. The flaw, tracked as CVE-2025-55177, affects certain versions of WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac, and could potentially allow attackers to gain unauthorized access to sensitive user data.

What’s the risk?

According to CERT-In’s advisory (CIVN-2025-0200), the vulnerability stems from improper authorization handling in linked device synchronization messages. By exploiting this flaw, hackers could trick WhatsApp into processing malicious content from arbitrary URLs on the victim’s device.

This could lead to exposure of personal chats, media, and sensitive user information. In some cases, the vulnerability has been observed alongside an Apple OS-level flaw (CVE-2025-43300), suggesting that it may have been leveraged in targeted cyberattacks.

Who is affected?

• WhatsApp for iOS versions prior to 2.25.21.73

• WhatsApp Business for iOS version 2.25.21.78

• WhatsApp for Mac version 2.25.21.78

Users running these versions are most at risk of exploitation.

What you can do

The government has strongly urged WhatsApp users to immediately update their apps to the latest available versions. WhatsApp has already released security patches to fix the flaw, which can be found on its official security advisories page.

Here are the steps users should follow:

1. Update WhatsApp – Go to the App Store (iOS/Mac) and install the latest version.

2. Enable auto-updates – Ensure future security patches are applied automatically.

3. Avoid suspicious links – Do not click on unknown links shared via WhatsApp, even from trusted contacts.

4. Check linked devices – Regularly review and remove any unknown devices from your WhatsApp account settings.

Why this matters

WhatsApp is one of the most widely used messaging platforms in India, with over 400 million users. Any breach in its security could expose massive amounts of personal and business data.

CERT-In’s warning highlights the growing trend of sophisticated cyberattacks that combine app-level and OS-level vulnerabilities. Staying updated is the best defense against such threats.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Sep 1, 2025 06:11 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347