The Sri Lanka Computer Emergency Readiness Team has issued a warning about a sophisticated zero-click attack targeting iPhone users, enabling criminals to hijack WhatsApp accounts without user interaction. The attack has already affected individuals from media and business sectors in the country.

Sri Lanka's computer security authority has alerted the public to a newly discovered zero-click attack exploiting WhatsApp on iPhones running outdated iOS 16 versions. According to the Sri Lanka CERT, the attack does not require any action from victims to succeed, representing a significant escalation in mobile security threats affecting the country.

Victims have reported receiving unauthorized WhatsApp messages requesting money transfers while compromised accounts showed no evidence of linked devices in their settings. In several cases, attackers have also assumed control of WhatsApp groups administered by affected users. Complaints have come from individuals across media organizations and the business community, indicating the attack's real-world impact within Sri Lanka.

A forensic investigation by an Italian security firm suggests attackers are exploiting vulnerabilities in WhatsApp's linked-device synchronization system. The threat primarily affects devices running iOS versions below 16.7.12 and is considered significantly more sophisticated than conventional QR-code phishing methods often used by cybercriminals.

Sri Lanka CERT has recommended immediate action for all users, including updating to the latest iOS and WhatsApp versions, enabling two-step verification and chat lock features, and verifying any unusual financial requests through alternative communication channels. Security experts note that the incident reflects the growing sophistication of financially motivated cybercriminals who increasingly rely on zero-click exploitation techniques, underscoring the importance of maintaining current device and application security updates.