Apple Alerts French Users Again Over Spyware Risks
France’s national Computer Emergency Response Team, CERT-FR, has confirmed that Apple has issued its fourth warning this year to users whose iCloud-linked devices may have been compromised in a targeted spyware campaign. The latest alerts were sent on September 3, 2025.

Officials did not disclose what triggered these alerts, but they emphasised that such notifications are part of Apple’s ongoing effort to warn individuals who may be under highly targeted attack. The previous alerts were distributed on March 5, April 29, and June 25.

Who Is Being Targeted & How Significant Is the Risk?
CERT-FR stated that this campaign aims at people by virtue of their role or public profile — journalists, lawyers, activists, politicians, senior officials, and members of strategic sector steering committees. The advisory did not reveal who is conducting the campaign or the specific methods being used, but it is consistent with zero-click attack vectors: attacks that exploit software vulnerabilities and require no action by the victim, such as clicking a malicious link.

Also noted was a recent chained exploit: a vulnerability in WhatsApp (CVE-2025-55177) combined with an Apple iOS bug (CVE-2025-43300) was reportedly used in attacks of this nature. Apple has introduced a hardware/software safeguard in newer iPhone models called Memory Integrity Enforcement (MIE), designed to combat memory corruption flaws commonly leveraged in these attacks.

Background: Apple’s Spyware Alert Practice
Apple has been sending notices of this kind since November 2021, alerting users when at least one device tied to their iCloud account might be compromised as part of sophisticated espionage or surveillance operations. Over 2025 alone, this is the fourth such alert issued in France, underlining both an uptick in frequency and the persistence of threat actors employing advanced means of attack.

These campaigns are especially concerning for civil society, journalism, and public office, given the sensitivity of information and the potential for abuse. In such cases, even a single compromise can have outsized implications for individual safety, privacy, public trust, and democratic institutions.

Expert Insights & Implications
While CERT-FR did not name the attackers or the precise payloads, cybersecurity experts observe a few broader trends:

  • The rise in zero-click exploits — especially chaining vulnerabilities across apps and operating systems — is making detection and prevention much harder.
  • The deployment of hardware protections like Memory Integrity Enforcement represents Apple’s recognition that software barriers alone are insufficient. These protections help guard against memory corruption that’s often exploited in zero-day or zero-click scenarios.
  • The increase in interest and investment in spyware technology globally heightens the risk that more actors — potentially state-affiliated or private vendors — are acquiring or producing sophisticated tools. A recent Atlantic Council report highlighted that the number of U.S. investors in spyware and surveillance firms rose from 11 in 2023 to 31 in 2024, surpassing investment levels in several other key nations.

Apple’s fourth alert in France this year serves as a stark reminder that targeted spyware attacks are escalating, not waning. For high-risk individuals — particularly those in public or advocacy roles — remaining vigilant is more important than ever. The combination of emerging technical protections, timely alerts, and transparency from vendors like Apple will be key to defending against these stealthy threats.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *