< Back to all clusters
[TECHNOLOGY] · Italy · 2 sources

WhatsApp zero-click hack lets attackers hijack iOS accounts, says Italian security team

Italian cybersecurity firm Forenser identified a new zero‑click attack on WhatsApp that can compromise iPhone users without any user interaction. The exploit leverages a vulnerability (CVE‑2025‑43300, possibly combined with CVE‑2025‑55177) in the way iOS processes certain images received in chat, allowing malware to install silently.

Once infected, the attacker can take control of the victim’s WhatsApp session, send fraudulent money‑request messages to recent contacts, and remain hidden because the session does not appear in the “linked devices” list. The team explained, “It is not a classic account theft, but a 0‑click attack: infection occurs without any user action.”

Forenser recommends updating WhatsApp, enabling two‑factor authentication, avoiding insecure Wi‑Fi, and regularly checking linked devices. The discovery highlights a sophisticated threat to millions of WhatsApp users on iOS 14‑16 devices.