Zero-Click WhatsApp Account Takeover Reportedly Targets iPhone Users on iOS 16


A reported zero-click WhatsApp account takeover campaign is targeting iPhone users running iOS 16, with victims seeing fraudulent money-transfer messages sent from their accounts even though they did not tap links, scan QR codes, share verification codes, or approve a linked device.

The cases were documented by Italian digital forensics firm Forenser, which said affected users had one clear pattern in common: their iPhones were running some version of iOS 16. The firm said the attackers appeared to use the victim’s WhatsApp account to contact recent chats while the app’s Linked Devices section showed no unknown session.

The suspected attack matters because it does not follow the usual WhatsApp hijacking playbook. Traditional scams often trick users into sharing a login code or pairing a device. In these cases, victims reported no such action, which points to a possible zero-click compromise of the device or app session.

What Victims Reported

According to the investigation, affected users noticed that their WhatsApp accounts had sent messages asking contacts for bank transfers or other payments. The messages came from the real account, which made the fraud harder for recipients to spot.

The victims checked WhatsApp’s Linked Devices menu but did not see an unknown device. That detail separates the incident from GhostPairing-style attacks, where a victim unknowingly links an attacker’s browser or desktop client.

The reported cases involved iPhone models ranging from iPhone 8 to iPhone 14, including iPhone X, XR, XS, 11, SE, 12, and 13 variants. The common factor was iOS 16, not one specific iPhone model.

Observed signWhy it matters
Money-transfer requests sent from the victim’s accountAttackers used trusted conversations to make fraud look real
No unknown device in Linked DevicesThe takeover did not look like normal device pairing abuse
No QR code scan or verification code sharingThe cases point toward a zero-click or device-level path
iPhones running iOS 16The same OS family appeared across the observed cases

The Suspected Exploit Chain

Forenser linked the cases to a likely chain involving two known vulnerabilities: CVE-2025-43300 in Apple’s ImageIO framework and CVE-2025-55177 in WhatsApp’s linked-device synchronization handling.

Apple describes CVE-2025-43300 as an out-of-bounds write issue where processing a malicious image file may result in memory corruption. The company said it was aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, and the flaw was fixed for older supported devices in iOS 16.7.12 and iPadOS 16.7.12.

For newer supported iPhones, Apple also fixed the same ImageIO issue in iOS 18.6.2 and iPadOS 18.6.2. That means users with iPhone XS and later should not stay on old iOS builds when a newer update is available.

WhatsApp’s Role in the Reported Attack

The WhatsApp side of the chain centers on CVE-2025-55177. In its 2025 security advisory, WhatsApp said incomplete authorization of linked-device synchronization messages could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.

WhatsApp also said the issue, when combined with an OS-level vulnerability on Apple platforms, may have been exploited in a sophisticated attack against specific targeted users. The affected versions included WhatsApp for iOS before v2.25.21.73, WhatsApp Business for iOS before v2.25.21.78, and WhatsApp for Mac before v2.25.21.78.

This is why users need both an iOS update and a WhatsApp update. Updating only one side may leave part of the attack surface exposed if the device or app still runs a vulnerable version.

Why the Attack May Not Show a Linked Device

The most unusual detail in the cases is the clean Linked Devices screen. Forenser said iOS logs from a compromised device showed repeated WhatsApp “resync” events, as if two clients were competing to maintain the same account session.

The firm’s lab work reproduced part of the scenario on a test device running a vulnerable iOS version. Its analysis suggests attackers may extract cryptographic material needed for a WhatsApp session handshake, then use it to start another WhatsApp client connected to the victim’s account.

That would explain why the victim’s phone stays logged in, why messages can be sent from the account, and why WhatsApp may not show a normal linked device entry.

What Users Should Do Now

The most important step is to update iOS. Users with iPhone 8, iPhone 8 Plus, or iPhone X should make sure they have installed iOS 16.7.12 or the latest version available for their device. Users with newer iPhones should move to the latest supported iOS release, since Apple’s iOS 18.6.2 update also patched CVE-2025-43300 for modern devices.

Users should also update WhatsApp immediately. The WhatsApp advisory confirms the patched iOS and Mac versions, so users should avoid running older builds of the app.

For people at higher risk, Apple recommends Lockdown Mode as an optional extreme protection for rare and highly sophisticated digital attacks. Apple says users should update their devices to the latest software before turning it on.

  • Update iOS to the latest version supported by the iPhone.
  • Update WhatsApp and WhatsApp Business from the App Store.
  • Restart the iPhone after updating both iOS and WhatsApp.
  • Check WhatsApp Linked Devices, even if this attack may not appear there.
  • Enable WhatsApp two-step verification as a general account-protection step.
  • Use Chat Lock for sensitive chats if you suspect account abuse.
  • Verify money requests by phone call, not through the same WhatsApp chat.

What to Do If Your WhatsApp Account Sent Messages You Did Not Write

If your WhatsApp account sent payment requests or other messages without your knowledge, treat the device as potentially compromised. First, update iOS and WhatsApp. Then reinstall WhatsApp or move the account to a clean device and re-authenticate it.

Forenser said updating WhatsApp or reinstalling the app on a new device with fresh authentication appeared to help remove the attacker’s session in observed cases. Users should also notify recent contacts not to trust financial requests sent during the suspected compromise window.

Victims should preserve evidence if the incident involves financial fraud. Screenshots, timestamps, device logs, bank-transfer requests, and suspicious messages may help forensic investigators or law enforcement understand what happened.

  1. Update iOS before using WhatsApp again.
  2. Update or reinstall WhatsApp from the App Store.
  3. Re-authenticate the account on a trusted device.
  4. Enable two-step verification in WhatsApp settings.
  5. Warn recent contacts by phone or SMS.
  6. Review bank activity if any payment was made.
  7. Consider professional forensic help for business or legal cases.

Why This Is a Different Kind of WhatsApp Threat

This incident shows how account takeover risk is changing. Many WhatsApp hijacking campaigns still depend on social engineering, but a zero-click model reduces the value of advice such as “do not click suspicious links.”

That does not mean user awareness has no role. People should still treat urgent money requests as suspicious, especially when they arrive through chat. However, the main defense here is patching, because the reported attack relies on vulnerable software rather than a user mistake.

Forenser’s findings also show why older iOS versions remain attractive targets. Attackers often focus on users who missed important security updates, especially when public technical details make older flaws easier to study.

Who Should Consider Lockdown Mode

Most users will not need Lockdown Mode, and Apple describes it as an extreme protection for a small number of people who may face highly sophisticated targeted attacks. That can include journalists, activists, executives, government workers, lawyers, and others with elevated risk.

For those users, Apple’s Lockdown Mode guide explains how the feature limits certain apps, websites, message attachments, device connections, and other areas that attackers may try to exploit.

For everyone else, the practical answer is simpler: keep iOS current, keep WhatsApp current, use two-step verification, and verify payment requests outside WhatsApp before sending money.

FAQ

What is the reported zero-click WhatsApp account takeover on iOS 16?

It is a reported attack pattern in which iPhone users running iOS 16 saw WhatsApp messages sent from their accounts without tapping links, scanning QR codes, sharing verification codes, or seeing unknown devices in Linked Devices.

Which vulnerabilities are linked to the WhatsApp iOS 16 attack reports?

The suspected chain involves CVE-2025-43300, an Apple ImageIO flaw, and CVE-2025-55177, a WhatsApp linked-device synchronization vulnerability. The Forenser report describes this as a likely model based on observed cases and lab reproduction.

How can iPhone users protect themselves?

Users should update iOS to the latest version supported by their device, update WhatsApp from the App Store, enable WhatsApp two-step verification, use Chat Lock for sensitive conversations, and verify money requests through a phone call instead of the same WhatsApp chat.

Why does the attack not appear in WhatsApp Linked Devices?

Forenser’s analysis suggests the attacker may create a parallel session using extracted WhatsApp session material rather than a normal linked-device flow. That could explain why victims saw no unknown device in the Linked Devices menu.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages