Subscribe to our WhatsApp Channel
Most WhatsApp scams need you to slip up first: click a bad link, share an OTP, scan a rogue QR code. Sri Lanka CERT has now warned of one that needs nothing from you at all. A ‘zero-click’ attack aimed at iPhone users can hand your entire WhatsApp account to a stranger while your phone sits untouched in your pocket. Here is what CERT flagged, and how to shut the door.
Sri Lanka CERT has officially announced that a highly sophisticated and dangerous cyberattack targeting iPhone users in Sri Lanka is currently spreading.
The attack falls into the ‘zero-click’ category. What makes it uniquely dangerous is that, unlike typical scams, it requires no action from the user at all: no clicking a link, no entering an OTP or verification code. Even if you do nothing, the attack lets cybercriminals seize complete control of your WhatsApp account.
How the Attack Actually Works
Hackers exploit a security flaw in WhatsApp’s ‘Linked Devices’ feature. By sending a covert background signal to your phone, they secretly connect their own computer or device to your WhatsApp account, entirely without your knowledge.
The Most Alarming Aspects of the Threat
Concealing the hacked device: the fraudulent devices the hackers link does not show up under Linked Devices in your WhatsApp settings, making it hard to tell your account has been compromised.
Defrauding your contacts: once inside, hackers message your family and friends, invent an urgent emergency, and ask them to deposit money into bank accounts.
Hijacking WhatsApp groups: if you administer any groups, the hackers seize your administrator privileges within them.
The Two Vulnerabilities Being Chained Together
According to international cybersecurity experts and Amnesty International’s Security Lab, the attack chains two separate flaws into a single exploit. The WhatsApp device-synchronization flaw (CVE-2025-55177) lets hackers take control of the device through a specially crafted message, while the Apple ImageIO flaw (CVE-2025-43300) complete control when the phone processes a maliciously crafted image sent over WhatsApp. The attack chain has been documented by The Hacker News and Security Affairs.
The Software Versions Experts Identified as Vulnerable
Apple iOS: all iPhones running iOS 16, particularly iOS 16.7.12 or older. WhatsApp Messenger (iOS): v2.25.21.73 or earlier. WhatsApp Business (iOS): v2.25.21.78 or earlier. WhatsApp for Mac: v2.25.21.78 or earlier.
Five Steps to Protect Yourself Immediately
1. Update your iOS software: on your iPhone, go to Settings > General > Software Update and install the latest version.
2. Update the WhatsApp app: open the Apple App Store, check for a new WhatsApp update, and install it.
3. Enable Two-Step Verification: in WhatsApp, go to Settings > Account > Two-Step Verification and add a PIN and email. The PIN is then required before any new device can be linked.
4. Disable media auto-download: temporarily turn off media auto-download in WhatsApp settings to stop malicious files downloading automatically.
5. Verify money requests with a phone call: if a friend or relative suddenly asks for money over WhatsApp, never transfer funds right away. Call them directly to confirm whether the request is genuine.
If your WhatsApp account is already behaving abnormally, or you strongly suspect it has been hacked, international security analysts advise not just updating the app but performing a full factory reset of the device.
Filing Complaints and Getting Support
If you suspect your WhatsApp account has been hacked, report it immediately to Sri Lanka CERT. Official hotline: 101 (9:00 a.m. to 8:00 p.m.). Email: report@cert.gov.lk.
www.cert.gov.lk | www.onlinesafety.lk
Cybersecurity Expert Asela Waidyalankara Weighs In
We contacted cybersecurity expert Asela Waidyalankara, who said the latest CERT warning should be taken with the utmost seriousness, because this is not the typical WhatsApp scam. In a standard scam the user has to click a suspicious link, hand over an OTP, or scan a QR code. A zero-click attack is fundamentally different: an account can be compromised without any conscious action by the user.
According to reports, the underlying issue lies in the process that synchronizes WhatsApp with linked iPhone devices. By exploiting it, an attacker could reach a victim’s account with no suspicious login prompt and no visible new linked device. In Sri Lanka, accounts compromised this way have been used to send fraudulent money requests and, in some cases, to take over WhatsApp groups the owner administered.
He stressed that users need not panic. The vulnerability is tied specifically to older iOS versions below iOS 16.7.12, and the most effective protection is simply keeping both the iPhone’s operating system and the WhatsApp app on their latest versions. Even so, the incident matters because it shows how the threat landscape is shifting: zero-click flaws can compromise even the most careful user.
His advice to WhatsApp users in Sri Lanka: update your iPhone and WhatsApp immediately, enable Two-Step Verification, and use features such as Chat Lock. Even if a message appears to come from someone you know, treat any sudden request for money or sensitive information with suspicion and verify it through a separate channel.
Join us to learn more about our fact-check investigations.
Facebook | Twitter | Instagram | Google News | TikTok | YouTube
Conclusion
Sri Lanka CERT has flagged a genuine zero-click WhatsApp vulnerability that can compromise iPhone accounts with no user interaction, chaining a WhatsApp device-sync flaw (CVE-2025-55177) with an Apple ImageIO flaw (CVE-2025-43300). It affects older builds: iOS below 16.7.12, WhatsApp Messenger v2.25.21.73 or earlier, and WhatsApp Business and Mac v2.25.21.78 or earlier.
The fix is straightforward: update iOS and WhatsApp, enable Two-Step Verification, disable media auto-download, and confirm any money request by phone. Cybersecurity expert Asela Waidyalankara stressed there is no need to panic, since keeping software patched is the single most effective defense against this attack.


