CVE-2025-30259: Meta WhatsApp Cloud Service

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.

Affected products

  • Meta WhatsApp Cloud Service

Published 2025-03-20. Last modified 2026-06-17.