A forensically confirmed zero-click campaign is actively hijacking WhatsApp accounts on iPhones running iOS 16, with attackers gaining full session control without requiring a single tap, scan, or interaction from their victims.
Italian digital forensics firm Forenser first identified the pattern after multiple iPhone users reported their WhatsApp accounts sending fraudulent wire-transfer requests to their contacts.
Every affected user shared the same profile: an iPhone running some version of iOS 16 spanning models from the iPhone 8 through the iPhone 14, including X, XR, XS, 11, SE, 12, and 13 variants, with no suspicious entries visible in the app’s Linked Devices section.
The accounts were actively being used by someone else, yet the victims had no record of authorizing any new device, scanning any QR code, or sharing any verification code.
0-Click WhatsApp Attack Targets iOS 16
Forensic analysis of iOS unified logs and sysdiagnose data from compromised devices revealed the attack’s technical signature: an abnormal, continuous stream of WhatsApp “resync” events, indicating that two separate clients were simultaneously attempting to maintain control of the same session.
The legitimate device and the attacker’s client were repeatedly authenticating with WhatsApp’s servers in an endless loop, which is exactly why messages were being sent from the victim’s number.
At the same time, the Linked Devices screen stayed empty; the attacker’s session was never registered as a traditional linked device.
Forenser team traced the attack to a two-vulnerability exploit chain. The first is CVE-2025-43300, a critical out-of-bounds write flaw in Apple’s ImageIO framework, the core library Apple uses across iOS to process and preview images.
An attacker exploiting this vulnerability can deliver a crafted malicious DNG image file that triggers memory corruption, writing data into memory regions beyond permitted bounds and opening a pathway to extract sensitive cryptographic material.
Apple patched this flaw in August 2025 after confirming it was being actively exploited as a zero-day across iOS, iPadOS, and macOS. However, every device analyzed by Forenser was still running an unpatched iOS 16 build.
The second vulnerability, CVE-2025-55177, is a WhatsApp-specific flaw stemming from incomplete authorization for linked-device synchronization messages.
It allowed an unauthenticated remote attacker to force a victim’s device to process content from an arbitrary URL simply by resending a tampered sync message, with no action required from the target.
The flaw affects WhatsApp for iOS versions below 2.25.21.73 and WhatsApp for Mac versions below 2.25.21.78.
Chained together, CVE-2025-43300 and CVE-2025-55177 allow an attacker to exfiltrate the cryptographic handshake material required to instantiate a new WhatsApp client elsewhere, invisibly bound to the victim’s account.
Forenser reproduced part of the attack in a controlled lab environment using a test device running a vulnerable iOS version, and the results matched the real-world cases precisely.
WhatsApp confirmed that approximately 200 people were targeted over three months, describing it as a “highly selective and advanced operation”.
Users who cannot upgrade immediately because their device’s maximum supported OS is iOS 16 should treat device replacement as an urgent priority, as Apple has not issued a dedicated iOS 16 patch for this issue.
Reinstalling WhatsApp on an updated device and completing a fresh authentication evicts the attacker’s parallel session, while enabling WhatsApp’s Two-Step Verification adds a credential hurdle the attacker must clear before completing any future enrollment.
Anyone at elevated risk, journalists, executives, and security professionals should consider enabling Apple Lockdown Mode, which disables the type of automatic protocol processing that zero-click exploits depend on.
One critical operational warning: if a contact receives a suspicious money request from your WhatsApp number, they must not reply in the same chat to verify it. The attacker’s session may intercept that reply before you ever see it.
This campaign follows the December 2025 GhostPairing operation, where attackers distributed WhatsApp pairing codes through fake Facebook lookalike domains to link attacker-controlled devices to victim accounts globally.
The convergence of publicly documented CVEs, a large population of unpatched iOS 16 devices, and financially motivated threat actors now using tooling previously reserved for nation-state operations means the exploitation window documented by Forenser is not a one-off incident.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.