WhatsApp and ImageIO: why the 2025 exploit pairing needed two patches
An authorization flaw in WhatsApp and a memory-safety flaw in Apple’s ImageIO had different fixes. The case shows why app updates and OS updates need separate verification.
INSIGHTS & PRACTICAL GUIDANCE
Clear explanations and useful steps from Short Circuit LLC. For original vulnerability findings and advisories, explore our research ↗.
An authorization flaw in WhatsApp and a memory-safety flaw in Apple’s ImageIO had different fixes. The case shows why app updates and OS updates need separate verification.
Unit 42 linked recovered spyware samples to a Samsung image-decoding flaw. The report also leaves gaps in the delivery and privilege-escalation chain that should not be filled with assumptions.
The public reports connect JavaScript, graphics, shared-memory and kernel flaws. Understanding the kit also requires separating its payloads and following Apple’s later backports.
Google reported five alternative iOS chains containing 23 exploits. Their version coverage, reuse and patch history explain why a small group of outdated devices can still matter.
Google’s record labels this flaw information disclosure but describes adding a Device Owner after provisioning. Keeping both parts visible changes what a device-management review needs to check.
Google fixed a certificate-verification error in Android’s wireless debugging service. The flaw concerns mutual authentication and shell access under adjacent or proximal conditions.
The CVE carries a 2025 identifier, but Google’s June 2026 bulletin reports the fix and targeted exploitation. The disclosed issue involves integer overflows and local privilege escalation.
Qualcomm’s flaw concerns alignment calculations during memory allocation. The public record describes local access and targeted exploitation, while device-specific patch coverage depends on the manufacturer.
The curl advisories describe a bearer token following the wrong destination and a proxy connection reused with the wrong identity. Each is a credential-state failure rather than memory corruption.