Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
| Software | From | Fixed in |
|---|---|---|
| whatsapp / whatsapp | 2.25.8.14 | 2.25.23.83 |
| whatsapp / whatsapp | 2.25.8.17 | 2.25.23.73 |
| whatsapp / whatsapp_business | 2.25.8.14 | 2.25.23.82 |