Apple recently disclosed a severe cybersecurity lapse: a “zero-click” zero-day flaw in its Messages app, exploited to deploy spyware—termed Graphite—on iPhones belonging to high-profile journalists and civil society members
What’s the Flaw?
Tracked as CVE-2025-43200, the vulnerability stemmed from a logic error in how Apple’s Messages app processed maliciously crafted media—specifically photos or videos shared via iCloud Links. This allowed attackers to execute code silently and without requiring any user interaction
Apple addressed the issue on February 10, 2025, rolling out patches across iOS 18.3.1, iPadOS 18.3.1 and 17.7.5, macOS Sequoia 15.3.1, Sonoma 14.7.4, Ventura 13.7.4, watchOS 11.3.1, and visionOS 2.3.1 These updates also remedied a second unnamed, actively exploited vulnerability (CVE‑2025‑24200), though Apple has not yet disclosed details about that flaw
Who Was Targeted?
Apple acknowledged that CVE‑2025‑43200 was used in a precise, sophisticated campaign targeting Italian journalist Ciro Pellegrino and an unnamed high-profile European journalist Forensic analysis by Citizen Lab confirmed that both were infected with Paragon’s Graphite spyware—an advanced tool designed for silent surveillance, capturing messages, emails, microphone and camera data, and location, all without user interaction
One infection occurred in January–early February 2025 on a device running iOS 18.2.1. It was stealthy enough that neither journalist likely noticed anything amiss . Apple informed the individuals of the targeting on April 29, 2025, through its threat notification system aimed at flagging suspected state-sponsored attacks.
What Is Graphite and Who’s Behind It?
Developed by Israel-based offensive cyber contractor Paragon, Graphite is marketed to state-level clients as a mercenary spyware platform . It can stealthily infiltrate Apple devices via zero-click vectors—such as corrupted media files—granting near-total access to device capabilities. It’s typically sold under national-security pretenses.
Evidence suggests both journalists were targeted from the same Apple account, codenamed “ATTACKER1”, indicating a single Paragon customer orchestrated the attack
Broader Graphite Backstory
Graphite has previously gained infamy. Notably, Meta-owned WhatsApp reported that Graphite was deployed against dozens of users globally, including Pellegrino’s colleague, journalist Francesco Cancellato, bringing the public count of known victims to at least seven
Earlier this week, Paragon announced it had ended contracts with the Italian government. The company cited Italy’s refusal to allow independent verification that the spyware wasn’t used against investigative journalists
Meanwhile, Italy’s Copasir (Parliamentary Committee for Republic Security) confirmed that Italian intelligence agencies used Graphite—but not on journalists—claiming it was deployed for law enforcement tasks including fugitive tracking, counter-terrorism, organized crime, smuggling, and counter-espionage .
Graphite’s infrastructure requires operator login credentials; every deployment generates logs. These logs reside on customer-controlled servers, not Paragon’s, introducing minimal external oversight
Risk and Global Implications
The Citizen Lab emphasized that journalists across Europe remain vulnerable to invasive digital surveillance, spotlighting how unchecked spyware proliferates and threatens privacy. The EU has already criticized such spyware use, calling for stringent export controls and stronger legal safeguards. These incidents are likely to intensify policy focus in Brussels and national capitals.
Apple’s threat notification system relies on threat intelligence; receiving an alert does not necessarily confirm infection—but signals suspicious activity.
Spyware Landscape: A Wider Context
While Graphite looms large, other spyware like Predator has also resurfaced. Recorded Future’s Insikt Group reports renewed Predator operations, including expansion into Mozambique and identification of new servers—highlighting persistent global spyware threats .
What You Can Do
- Update your devices: Ensure your Apple products are updated to the latest iOS, macOS, watchOS, or visionOS versions.
- Stay alert: If you receive a threat notification from Apple, treat it seriously—even if your device seems normal.
- Advocate for change: Encourage stronger legal frameworks to regulate commercial spyware and promote transparency in its deployment.
As zero-click spyware becomes more sophisticated, this case highlights the need for vigilance, transparency, and accountability. Users and policymakers must recognize that threats once limited to espionage circles can now penetrate the heart of civil society.
Please subscribe to the Newsletter so that you do not miss any critical update
