Loading video...
Video Failed to Load
We triggered WhatsApp 0-click on iOS/macOS/iPadOS. CVE-2025-55177 arises from missing validation that the [Redacted] message originates from a linked device, enabling specially crafted DNG parsing that triggers CVE-2025-43300. Analysis of Samsung CVE-2025-21043 is also ongoing.
279,970 views • 1 year ago •via X (Twitter)
29 Comments

Did they pay for it? I recently reported a one-click DOS that they refused to pay for, and I’m currently appealing.

Anything beyond the crash? RCE?

Impressive analysis. Addressing such validation gaps advances security and user trust. Consistent encryption and code reviews like these push global standards forward.

Zero-click chains like this are wild No user action, full compromise Makes you rethink how much surface area is tied to linked devices Curious if the Samsung path has similar pivot potential

The phone number is blurred out on the command line but full phone number is visible in the iPadOS

@0xKira233 Great blog posts! Curious about the exploitation of the Samsung vuln ;)

So you need to be same network?

@adibmedx Zero-click exploits are wild! As a Shopify dev, does this impact WhatsApp Business API integrations?

@grok est ce une nouvelle vulnérabilité ?

Nice PoC! There’s more left unreported in ImageIO, just need another entry for 0-click. Very close to being a lucrative payout

Hi i need to toke to you private

Did you ever look into the Samsung one? Might be worth a peek -

did u get permission?

😮

Is this exploit open source or paid?

impressive

@grok is that true

Please DM me, I am interested to learn more about the work you have done and how we can collaborate further together

关注验证链路与设备来源,尽快强制推送修复

Can someone explain how a remote attacker connects to a victim's local network?

awesome!!!

Exciting to see such creative red team tactics! As agent-based threats get more advanced, rock-solid audit frameworks for Linux C2 payload transparency will be crucial here. What’s the top feature you want for a Linux agent auditor? FenzAI, Bloodtest Your AI Agents.

👋🤠

@grok wytłumacz jak to działa i jakie są zagrożenia

I need that exploit🥲

I've been collecting evidence for two months following a sophisticated hack that compromised all smart devices in my home, personal phone, and work laptop. I have ample evidence on CVE-43300 and how it occured, and who did it Who can I share this info with?

@grok what is the POC they're using

See similar bug class on Samsung, champ? Auth bypass into media parse?

CAN U GIMME THE POC!
