WhatsApp Exploit Privately Disclosed To Meta At The Pwn2Own Ireland
During the Pwn2Own Ireland 2025 hacking competition, Team Z3 opted for a private coordinated disclosure to Meta instead of publicly demonstrating a potential zero-click remote code execution (RCE) vulnerability in WhatsApp.
During the Pwn2Own Ireland 2025 hacking competition, Team Z3 opted for a private coordinated disclosure to Meta instead of publicly demonstrating a potential zero-click remote code execution (RCE) vulnerability in WhatsApp.
The competition was held in Cork, Ireland, from October 21-23, 2025, and featured a $1 million bounty for the WhatsApp exploit. This drew significant attention due to WhatsApp's large user base of three billion users.
Team Z3 decided against a live public demonstration, citing that their research was not ready. The Zero Day Initiative (ZDI), the event organizers, confirmed this decision. Despite the withdrawal, an initial assessment by ZDI analysts will occur before the findings are handed over to Meta engineers.
Meta, the parent company of WhatsApp and co-sponsor of the event, expressed interest in the findings to enhance the app’s defenses against threats such as zero-click attacks. This aligns with ethical hacking norms, providing Meta up to 90 days post-event to address any identified issues.
The competition was held in Cork, Ireland, from October 21-23, 2025, and featured a $1 million bounty for the WhatsApp exploit.
The event highlights the importance of bug bounties and coordinated disclosures in cybersecurity. While the Pwn2Own Ireland competition awarded $1,024,750 for 73 unique zero-days across various devices, the WhatsApp vulnerability underscores the hidden risks in widely used applications.
No specific details about the vulnerability, such as affected versions or CVE assignment, have been disclosed. However, experts anticipate a swift response from Meta to prevent potential exploitation.
Overall, Team Z3's approach emphasizes responsible vulnerability disclosure, potentially preventing widespread harm. The cybersecurity community is closely monitoring Meta’s forthcoming security advisories.
Based on reporting by Cyber Security News.
