A series of incidents identified in Italy during May 2026 revealed that WhatsApp accounts on iPhones can be compromised without any action from the victim, such as clicking on links or sharing codes. The case was analyzed by INCIBE-CERT, the Spanish cybersecurity incident response center, and showed that victims discovered their accounts had sent messages to recent contacts requesting money transfers, despite not having written those requests themselves. The affected devices ranged from iPhone 8 to iPhone 14 and had in common the use of different versions of iOS 16.
The forensic investigation linked the incidents to a combination of two vulnerabilities. The first, identified as CVE-2025-43300, affected Apple's ImageIO component and allowed processing a malicious image file to cause memory corruption. Apple confirmed awareness of a report stating the flaw could have been exploited in an extremely sophisticated attack targeting specific individuals. The second flaw, CVE-2025-55177, affected WhatsApp for iOS and allowed another user to trigger the processing of external content on the victim's device.
The attack became especially dangerous because the money request came from the victim's actual WhatsApp account, not from an unknown number trying to impersonate them, which could deceive friends or family. INCIBE notes that the exact use of the two vulnerabilities to explain all new incidents results from ongoing forensic analysis, and is not an attack chain definitively demonstrated in all cases.
The main protection measure is to update both the operating system and the application. iOS 16.7.12, released in September 2025, patched Apple's flaw, and WhatsApp patched its vulnerability starting from version 2.25.21.73. The recommendation is to always install the latest version compatible with the device. The analyzed cases were identified in Italy and do not mean all iPhone users are being targeted by this type of attack, but they demonstrate that an account can be compromised without the traditional click on a link.




