← back
CVE-2025-30259lowobserved exploitation

CVE-2025-30259

30Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 3.5epss 0.2%
from disclosure to weapon
Published on NVDMar 19
VulnCheckMar 19
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
yesVulnCheck
The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N