Loading video...

Video Failed to Load

Go Home

We triggered WhatsApp 0-click on iOS/macOS/iPadOS. CVE-2025-55177 arises from missing validation that the [Redacted] message originates from a linked device, enabling specially crafted DNG parsing that triggers CVE-2025-43300. Analysis of Samsung CVE-2025-21043 is also ongoing.

279,970 views • 1 year ago •via X (Twitter)

29 Comments

سًًٌٌٌٌٌٍَََََََُُُُِِِِِِّّّّّْْْْْٰٰٰٰٕٕٕٓٔٓٓٓٓٔ's profile picture
سًًٌٌٌٌٌٍَََََََُُُُِِِِِِّّّّّْْْْْٰٰٰٰٕٕٕٓٔٓٓٓٓٔ1 year ago

Did they pay for it? I recently reported a one-click DOS that they refused to pay for, and I’m currently appealing.

Basset 🏴‍☠️'s profile picture
Basset 🏴‍☠️11 months ago

Anything beyond the crash? RCE?

Jawad Al Hashmi's profile picture
Jawad Al Hashmi1 year ago

Impressive analysis. Addressing such validation gaps advances security and user trust. Consistent encryption and code reviews like these push global standards forward.

Fake Cr7's profile picture
Fake Cr711 months ago

Zero-click chains like this are wild No user action, full compromise Makes you rethink how much surface area is tied to linked devices Curious if the Samsung path has similar pivot potential

BTCAlchemist 🔮🛡️'s profile picture
BTCAlchemist 🔮🛡️11 months ago

The phone number is blurred out on the command line but full phone number is visible in the iPadOS

esjay's profile picture
esjay1 year ago

@0xKira233 Great blog posts! Curious about the exploitation of the Samsung vuln ;)

JACKY JACK's profile picture
JACKY JACK11 months ago

So you need to be same network?

Giuseppe Valenza's profile picture
Giuseppe Valenza10 months ago

@adibmedx Zero-click exploits are wild! As a Shopify dev, does this impact WhatsApp Business API integrations?

@schy's profile picture
@schy11 months ago

@grok est ce une nouvelle vulnérabilité ?

zodttd's profile picture
zodttd11 months ago

Nice PoC! There’s more left unreported in ImageIO, just need another entry for 0-click. Very close to being a lucrative payout

Dridex Os's profile picture
Dridex Os11 months ago

Hi i need to toke to you private

bin2bug's profile picture
bin2bug11 months ago

Did you ever look into the Samsung one? Might be worth a peek -

FTB Tunji. 🪁's profile picture
FTB Tunji. 🪁11 months ago

did u get permission?

Giedrius Trump's profile picture
Giedrius Trump11 months ago

😮

Rx1🚩's profile picture
Rx1🚩11 months ago

Is this exploit open source or paid?

piperpwn's profile picture
piperpwn11 months ago

impressive

Abobakr's profile picture
Abobakr11 months ago

@grok is that true

Hadi Hosn's profile picture
Hadi Hosn11 months ago

Please DM me, I am interested to learn more about the work you have done and how we can collaborate further together

狐.eth 🦊🌒's profile picture
狐.eth 🦊🌒11 months ago

关注验证链路与设备来源,尽快强制推送修复

مهرداد بختیار's profile picture
مهرداد بختیار11 months ago

Can someone explain how a remote attacker connects to a victim's local network?

zer0ptr's profile picture
zer0ptr11 months ago

awesome!!!

Fenz AI - 🏥 for Agents's profile picture
Fenz AI - 🏥 for Agents11 months ago

Exciting to see such creative red team tactics! As agent-based threats get more advanced, rock-solid audit frameworks for Linux C2 payload transparency will be crucial here. What’s the top feature you want for a Linux agent auditor? FenzAI, Bloodtest Your AI Agents.

wajdi bengayed's profile picture
wajdi bengayed11 months ago

👋🤠

Running Man's profile picture
Running Man11 months ago

@grok wytłumacz jak to działa i jakie są zagrożenia

نادرباغی's profile picture
نادرباغی11 months ago

I need that exploit🥲

Kazebeat's profile picture
Kazebeat11 months ago

I've been collecting evidence for two months following a sophisticated hack that compromised all smart devices in my home, personal phone, and work laptop. I have ample evidence on CVE-43300 and how it occured, and who did it Who can I share this info with?

ˢⁱⁿ⁹⁹ˣˣ's profile picture
ˢⁱⁿ⁹⁹ˣˣ11 months ago

@grok what is the POC they're using

Zanka's profile picture
Zanka11 months ago

See similar bug class on Samsung, champ? Auth bypass into media parse?

Rohith N's profile picture
Rohith N8 months ago

CAN U GIMME THE POC!

Related Videos