Skip to finding
important · Zero-click

A demonstrated zero-click chain on unpatched iOS 16 can silently clone a WhatsApp session.

Affects

WhatsApp for iOS on iPhones running vulnerable iOS 16 releases.

Forenser demonstrated the result with the current WhatsApp application on iOS versions earlier than 16.7.12 and without victim interaction.

Detail and 4 sources

The researchers associate image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177, but they did not publish the initial artifact or prove the complete composition.

The demonstrated boundary is iOS 16.7.12; revocation of previously exposed session material remains unknown, and affected versions reach end-of-life hardware.

Chain to watch
Attacker remotely targets a WhatsApp account on an iPhone running iOS earlier than 16.7.12.→↓An unpublished zero-click trigger compromises the device at the OS level; Forenser associates the observed image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177.→↓Critical WhatsApp session-handshake material is extracted from the compromised device.→↓A malicious PC client authenticates as the victim without creating a visible Linked Devices entry.→↓The attacker reads recent chats and sends messages that recipients see as coming from the victim.→↓The public demonstration does not reveal the initial delivery artifact or prove that CVE-2025-43300 and CVE-2025-55177 are the complete chain.
Unverified chainObtain Forenser's trigger artifact or technical report, reproduce the attacker-to-device transition, and test session cloning separately across the iOS 16.7.12 boundary.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026