CVE-2025-30259

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Mar 20, 2025

Summary

CVE-2025-30259: WhatsApp cloud service, prior to an expected update in late 2024, failed to block specifically crafted PDF files. This oversight allowed attackers to bypass sandbox protection mechanisms and gain unauthorized remote access to messaging applications, resulting in Android malware, such as that linked to BIGPRETZEL, being installed in the wild during 2024.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share