Home » Technology » Page 3129

WhatsApp Zero-Click Hack Targets Apple Devices


A serious security vulnerability has been discovered within WhatsApp, perhaps impacting millions of Apple device users. Meta,the parent company of WhatsApp,is currently rolling out emergency updates to address the flaw,which enables attackers to inject malicious code without any user interaction – a so-called “zero-click” attack.

The vulnerability centers around a flaw in how WhatsApp automatically synchronizes messages on iPhones, iPads, and Mac computers. Exploiting this weakness, coupled with existing vulnerabilities in Apple’s operating systems, could allow attackers to install refined spyware via a specially crafted link. Crucially, users do not need to click on anything for the exploit to work.

Which Versions Are Affected?

The following WhatsApp versions are susceptible to this exploit and require immediate updating:

Platform Vulnerable Version Recommended Action
iOS 2.25.21.73 or older Update to the latest version
whatsapp Business (iOS) 2.25.21.78 or older Update to the latest version
macOS 2.25.21.78 or older Update to the latest version

The vulnerability, tracked as CVE-2025-55177, is especially hazardous because it exploits a weakness in the “Image I/O” library of Apple’s operating systems, allowing for the execution of malicious code thru manipulated images.

Did You Know? Zero-click exploits are among the most dangerous types of cyberattacks, as they require no action – or even awareness – from the user.

Activist Warns of Active Exploitation

Security researcher Donncha Ó Cearbhaill,Head of the Security Lab at Amnesty International,has reported that the vulnerability is already being actively exploited by attackers. Some WhatsApp users have received notifications indicating that they may have been targeted with a malicious message.While it remains unclear if devices have been fully compromised, Ó Cearbhaill strongly recommends a full factory reset of devices alongside keeping both operating systems and WhatsApp updated.

What Should Users Do?

Meta urges all affected users to update their WhatsApp application immediately. In addition, it is critical to ensure your Apple device’s operating system (iOS, iPadOS, or macOS) is also updated to the latest version to patch the related Image I/O vulnerability.

Understanding Zero-Click exploits

zero-click exploits represent a notable escalation in cybersecurity threats. Traditionally, attackers relied on tricking users into clicking malicious links or opening infected attachments.However, zero-click exploits bypass this requirement, leveraging vulnerabilities in software to gain access without any user interaction.This makes them extremely difficult to defend against.

Pro Tip: Regularly updating your software is the most effective way to protect yourself from known vulnerabilities. Enable automatic updates whenever possible.

The rise of zero-click attacks underscores the importance of a layered security approach. This includes using strong passwords, enabling two-factor authentication, and being cautious about sharing personal information online.

Frequently Asked Questions About the WhatsApp Hack

  • What is a WhatsApp zero-click hack? A zero-click hack allows attackers to compromise a device without requiring any action from the user, like clicking a link.
  • how can I protect myself from this WhatsApp vulnerability? Update WhatsApp and your Apple device’s operating system to the latest versions immediately.
  • What is CVE-2025-55177? It’s a unique identifier for this specific security vulnerability, allowing researchers and security teams to track and address it.
  • Is my data at risk if I received a warning from WhatsApp? It’s possible. While not confirmed, experts recommend a factory reset as a precautionary measure.
  • What platforms are affected by this WhatsApp security issue? iPhones, iPads, and Mac computers running older versions of WhatsApp and their respective operating systems are affected.
  • How ofen do zero-click exploits occur? While relatively rare due to their complexity, zero-click exploits are considered the most dangerous type of cyberattack, and their occurrence is increasing.
  • What is the Image I/O library? It’s a component of Apple’s operating systems responsible for handling images, and a vulnerability within it allows attackers to inject malicious code.

Are you concerned about the increasing sophistication of cyberattacks? What steps are you taking to protect your personal data?


What are the potential consequences of a accomplished zero-click exploit on a WhatsApp user’s Apple device?

Exploiting WhatsApp Zero-Click Vulnerability on Apple Devices: An Urgent Security Alert

Understanding the zero-Click Threat to WhatsApp Security

A recently disclosed WhatsApp vulnerability poses a important risk to Apple device users – iPhones, iPads, and Macs.This isn’t your typical phishing scam or malware download. This is a zero-click exploit, meaning it requires no interaction from the user to compromise their device. No clicking links, opening attachments, or even answering a call. The attack vector leverages a flaw within WhatsApp’s core functionality, specifically how it processes certain image files. This makes it notably perilous, as even simply receiving a specially crafted image can lead to complete device takeover. WhatsApp zero-day exploit scenarios are increasingly common, demanding proactive security measures.

How the Exploit Works: Deep Dive into the Technical Details

The vulnerability,reportedly affecting WhatsApp versions prior to the latest updates,centers around the processing of GIF images. A maliciously crafted GIF can trigger a buffer overflow in WhatsApp’s image processing engine.

Here’s a breakdown of the process:

  1. Malicious GIF Delivery: An attacker sends a specially crafted GIF image to the target via WhatsApp.
  2. Buffer Overflow: when whatsapp attempts to process the GIF, the malicious code overflows a buffer in the application’s memory.
  3. Remote Code Execution (RCE): This overflow allows the attacker to inject and execute arbitrary code on the victim’s device.
  4. Device compromise: Once RCE is achieved,the attacker gains control of the device,potentially accessing messages,contacts,photos,and other sensitive data. They can also install additional malware or monitor the user’s activity.

This exploit bypasses Apple’s security features as it operates within the WhatsApp sandbox, exploiting a weakness in the application itself, rather than the operating system directly. iOS security relies heavily on application sandboxing, but vulnerabilities within those sandboxes can be devastating.

Affected Devices and WhatsApp Versions

Currently, all Apple devices running vulnerable versions of WhatsApp are at risk. This includes:

iPhones: All models running iOS versions susceptible to the exploit.

iPads: All models running iPadOS versions susceptible to the exploit.

Macs: Macs running WhatsApp Desktop (specifically versions prior to the patch).

Determining the exact affected versions is crucial. WhatsApp typically releases updates to address these vulnerabilities quickly. Check the App Store or the WhatsApp download page (https://www.whatsapp.com/download?lang=de) for the latest version. staying current with WhatsApp updates is the most effective defense.

Real-World Implications and Known Attacks

While details are often kept confidential, several instances of this type of exploit have been documented.

2019 NSO Group Exploit: In 2019, a similar WhatsApp vulnerability was exploited by the NSO Group, an Israeli cyberarms firm, to target human rights activists and journalists. This attack, also a zero-click exploit, allowed attackers to install spyware on victims’ phones.

Targeted Surveillance: These exploits are frequently used for targeted surveillance,often by governments or state-sponsored actors,to monitor individuals of interest.

Financial Gain: While less common, attackers can also leverage these vulnerabilities for financial gain, such as stealing banking credentials or conducting corporate espionage.

The potential for misuse is significant, highlighting the urgency of addressing this threat. Mobile security threats are constantly evolving, and zero-click exploits represent a particularly complex and dangerous trend.

Mitigation Strategies: Protecting Your Apple Devices

Here’s what you can do right now to protect yourself:

  1. Update WhatsApp Instantly: This is the most important step. Update to the latest version of WhatsApp available on the App Store. WhatsApp security updates are released frequently to address newly discovered vulnerabilities.
  2. Enable Auto-Updates: Configure your Apple device to automatically install app updates. This ensures you receive security patches as soon as they are available.
  3. Review App Permissions: Regularly review the permissions granted to WhatsApp. While not directly related to this exploit, limiting unneeded permissions can reduce the potential damage if your device is compromised.
  4. Be Cautious with Unknown Senders: While this is a zero-click exploit, exercising caution with unknown senders is always a good practice.
  5. Consider Endpoint Detection and Response (EDR) Solutions: For high-risk individuals, consider using an EDR solution designed to detect and respond to advanced threats on mobile devices.
  6. Enable Two-Step Verification: Add an extra layer of security to your WhatsApp account by enabling two-step verification.

Benefits of Proactive Security Measures

Investing in proactive security measures offers several benefits:

Data Protection: Safeguards your personal and sensitive data from unauthorized access.

Privacy Preservation: Protects your privacy by preventing surveillance and monitoring.

Financial security: Reduces the risk of financial loss due to fraud or theft.

Reputational Protection: Protects your reputation by preventing

0 comments
0 FacebookTwitterPinterestEmail

Upcoming Items Exchangeable with September Exchange Tickets in Fate/Grand Order (2025)

by Sophie Lin - Technology Editor


September 2025 Exchange Ticket Details Revealed

September 2025 Exchange Ticket Details Revealed

Players can soon redeem September exchange tickets, acquired through consistent participation in login bonuses and daily missions. The availability of these tickets and the items they unlock are subject too specific timeframes. This year’s offerings include several sought-after items, providing players with valuable rewards for their dedication.

Ticket Distribution and Redemption Timeline

The September exchange tickets for 2025 will be distributed through continuous login bonuses starting Monday, September 1st, 2025, at 4:00 AM, and concluding on Wednesday, October 1st, 2025, at 3:59 AM.Daily missions will also provide opportunities to earn these tickets throughout September, running from 0:00 on September 1st until 23:59 on September 30th, 2025.

Redemption of these tickets will be possible until 23:59 on Wednesday, December 31st, 2025. Notably August 2025 exchange tickets have a separate redemption deadline, ending on Sunday, november 30th, 2025, at 23:59.Players should plan accordingly to ensure they do not miss out on valuable rewards.

Available Exchangeable Items

The following items are currently available for exchange using September 2025 tickets:

item Name Description
Etheric Photocontainer A container used for storing etheric energy.
Rainbow Thread Ball essential material for crafting vibrant items.
Meteor Horse Stool A unique stool crafted from meteor fragments.
Dragon’s Fang A powerful item said to contain a dragon’s essence.
Forgotten Ash Mysterious ash with unknown properties.

Did You Know? Exchange tickets are cumulative. If a Player obtains multiple September tickets, they can be used concurrently for multiple item redemptions.

The selection of exchangeable items is refreshed monthly, ensuring ongoing opportunities for players to acquire new and exciting rewards. Additionally, tickets acquired across month boundaries will correspond their exchange eligibility to the ticket’s designated month.

Understanding Exchange Tickets: A Player’s Guide

Exchange tickets represent a valuable system within the game, designed to reward consistent player engagement. These tickets provide access to exclusive items, enhancing the gaming experience and providing strategic advantages. It’s crucial to understand the distribution and redemption timelines to maximize their benefits. Regularly checking for updates on available items is recommended, as the selection changes monthly.

Pro Tip: Keep track of your tickets and plan your exchanges strategically, prioritizing items that best suit your gameplay style.

frequently asked Questions

What are September exchange tickets used for?

September exchange tickets are used to redeem exclusive in-game items, such as Etheric Photocontainers and Dragon’s Fang.

How do I earn September exchange tickets?

You can earn these tickets through continuous login bonuses and by completing daily missions throughout September 2025.

When do the September exchange tickets expire?

September exchange tickets are valid until 23:59 on Wednesday, December 31st, 2025.

Can I use multiple September exchange tickets at once?

Yes, if you have multiple tickets, you can exchange them all at once for multiple items.

What happens if I receive an august exchange ticket in September?

The items available for exchange will still correspond to the August ticket’s designated month, but the receiving player must remember the August tickets expire sooner than September ones.

What items would you most like to see offered through future exchange ticket programs? Share your thoughts in the comments below and let us know your experience with the current selection!


Which 5-Star Servant is consistently popular and expected to have high demand?

Upcoming Items Exchangeable with September Exchange Tickets in Fate/Grand Order (2025)

September Exchange Ticket highlights: A Master’s Guide

fate/Grand Order (FGO) players eagerly anticipate the monthly Exchange Ticket rounds, and September 2025 is shaping up to be a especially exciting one.These tickets offer a fantastic opportunity to acquire valuable Servants and Craft Essences, bolstering your roster without relying solely on gacha luck. This guide details the expected and highly sought-after items available for exchange, helping you strategize your choices for optimal team building and challenge completion. We’ll cover everything from limited-time Servants to essential Farming tools.

Confirmed & Highly Probable Exchangeable Servants

based on past trends and community speculation, here’s a breakdown of Servants likely to be available for exchange with September 2025’s Exchange Tickets. Keep in mind that official announcements from TYPE-MOON and Aniplex are the final authority.

5-Star Servants:

Artoria Pendragon (Saber): A consistently popular choice for her strong performance in various quests. Expect high demand.

Gilgamesh (Archer): Remains a top-tier DPS Servant, valuable for both farming and challenging content.

Merlin (Caster): The quintessential support Caster, essential for many team compositions.

Tamamo no Mae (Caster): Another powerful caster, offering both offensive and defensive capabilities.

Skadi (Saber): A cornerstone of Quick teams, still highly relevant despite power creep.

4-Star Servants:

Heracles (Berserker): A reliable and powerful Berserker, excellent for soloing and general damage.

Jeanne d’Arc (Ruler): A strong defensive Ruler, invaluable for surviving difficult battles.

Lancelot (Saber): A potent Saber with strong offensive capabilities.

Altera (Saber): A powerful, if somewhat niche, Saber known for her high damage output.

Hans Christian Andersen (Caster): A surprisingly effective support Caster, particularly for low-rarity teams.

Essential Craft Essences for Exchange

Beyond Servants, Exchange Tickets are invaluable for obtaining key Craft Essences. these can substantially enhance your team’s performance.

5-Star Craft Essences:

Holy Grail: Global plus stats, always a solid choice.

Monumental Blessing of the Goddess: Critical Hit damage boost, ideal for DPS Servants.

Black Grail: Max HP and Critical Hit damage, a staple for many farming teams.

4-Star Craft Essences:

False Holy Grail: A more accessible version of the Holy Grail, providing valuable stat boosts.

Knight’s Prider: Critical Hit rate boost, useful for enhancing DPS output.

Limited/Event Specific CEs: Keep an eye out for Craft Essences from past events that may reappear for exchange. These often provide unique benefits tailored to specific content.

Strategic considerations: Maximizing Your Exchange Tickets

Planning your exchanges is crucial. Here’s how to make the most of your September 2025 Exchange Tickets:

  1. Identify Team needs: Assess your current roster and identify gaps in your team compositions. Do you need more DPS, support, or defensive capabilities?
  2. Prioritize Limited Servants: If a limited-time Servant you missed is available, prioritize exchanging for them. These opportunities are frequently enough rare.
  3. Consider Future Events: anticipate upcoming events and choose Servants and Craft Essences that will be beneficial for those challenges.
  4. Farming Efficiency: Invest in Craft Essences that boost farming efficiency, such as those that increase QP or EXP gain.
  5. **Don’t Neglect Low-Rarity
0 comments
0 FacebookTwitterPinterestEmail
Newer Posts
Older Posts

Adblock Detected

Please support us by disabling your AdBlocker extension from your browsers for our website.