CVE-2025-30259
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Mar 20, 2025
Summary
CVE-2025-30259: WhatsApp cloud service, prior to an expected update in late 2024, failed to block specifically crafted PDF files. This oversight allowed attackers to bypass sandbox protection mechanisms and gain unauthorized remote access to messaging applications, resulting in Android malware, such as that linked to BIGPRETZEL, being installed in the wild during 2024.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.