Non-interactive attacks against WhatsApp accounts on iPhones running iOS 16

Posted date 28/08/2026

During May 2026, several cases were identified in Italy involving WhatsApp accounts being used without authorisation on iPhone devices running various versions of iOS 16. The first cases were reported to the Italian digital forensics firm Forenser over several days that month, after users discovered that messages requesting money transfers had been sent from their accounts to recent contacts. Forensic investigations carried out on these devices identified common elements across the incidents, including the absence of unknown devices in the ‘Linked Devices’ section and the fact that the victims had not previously carried out any pairing action.

The cases analysed affected various iPhone models, ranging from the iPhone 8 to the iPhone 14, all running some version of iOS 16. Forenser linked the incidents to a possible chain involving CVE-2025-43300, an out-of-bounds write vulnerability in Apple’s ImageIO, and CVE-2025-55177, an insufficient authorisation vulnerability in WhatsApp’s linked device synchronisation messages. The latter allowed an unrelated user to trigger the processing of content from an arbitrary URL on the target device. Both vulnerabilities had already been patched by Apple and WhatsApp during 2025, although devices still running vulnerable versions of iOS 16 could remain exposed.

As for the measures taken, WhatsApp had fixed CVE-2025-55177 in WhatsApp for iOS via version 2.25.21.73 and in WhatsApp Business for iOS and WhatsApp for Mac via version 2.25.21.78. Apple, for its part, patched CVE-2025-43300, amongst other vulnerabilities, in iOS 16.7.12 and subsequently in more recent versions of its operating systems. In the cases involving the 2025 vulnerabilities, WhatsApp also notified fewer than 200 users it considered potentially affected and recommended keeping both WhatsApp and the operating system up to date, whilst Apple reported that it had received indications that CVE-2025-43300 had been exploited against specific individuals.

As the incident currently stands, the research published by Forenser continues to describe the combined use of CVE-2025-43300 and CVE-2025-55177 as a technical hypothesis to explain the cases observed on devices running iOS 16. The forensic evidence gathered includes anomalous ‘resync’ events in WhatsApp logs and errors related to image processing, and Forenser notes that it has managed to reproduce part of the scenario in a controlled environment. However, WhatsApp has not issued a specific statement confirming that the new cases from May 2026 are the result of this same chain of vulnerabilities; therefore, this particular exploit cannot be officially attributed to WhatsApp beyond the technical link established by the forensic investigation.