Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in the wild.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| 2.25.8.14 (including) | 2.25.23.83 (excluding) | ||
| 2.25.8.17 (including) | 2.25.23.73 (excluding) | ||
| Whatsapp_business | 2.25.8.14 (including) | 2.25.23.82 (excluding) |