CISA Issues Warning on Exploited iOS 0-Click Vulnerability in the Wild

A sophisticated spyware campaign leveraging a zero-click vulnerability in Apple’s iOS has targeted European journalists, marking a significant escalation in digital surveillance against press freedom.

Forensic analysis confirms Paragon’s Graphite mercenary spyware exploited CVE-2025-43200, a critical flaw patched in February 2025 but actively weaponized months earlier.

Apple iOS Zero-Click Vulnerability (CVE-2025-43200)

The attack exploited a logic flaw in iOS that allowed maliciously crafted photos or videos shared via iCloud Links to trigger remote code execution, without requiring user interaction.

Dubbed a “zero-click” exploit, it enabled Graphite spyware to infiltrate iPhones running iOS 18.2.1, leaving no visible traces of infection.

Key technical details:

  • Attack Vector: A hidden iMessage account labeled ATTACKER1 delivered the exploit.
  • Infrastructure: Compromised devices connected to server 46.183.184[.]91, hosted by EDIS Global, which matched Citizen Lab’s Fingerprint P1 identifier for Graphite.
  • Patch Timeline: Apple resolved the vulnerability in iOS 18.3.1 (February 10, 2025), but delayed public disclosure until June 11, 2025.

“The zero-click attack deployed here was mitigated as of iOS 18.3.1,” Citizen Lab noted, emphasizing the critical need for timely updates.

Targeted Journalists and News Organizations

Forensic evidence confirms two high-profile cases:

  1. Prominent European Journalist (anonymous):
    • Compromised January–February 2025 via ATTACKER1.
    • Device logs revealed sustained communication with Paragon’s server.
  2. Ciro Pellegrino (Head of Fanpage, it’s Naples newsroom):
    • Targeted using the same ATTACKER1 account, linking both cases to a single Paragon operator.

A third journalist, Francesco Cancellato (Fanpage.it editor), received a WhatsApp notification about Graphite targeting in January 2025, though no infection was confirmed.

The pattern suggests a coordinated effort to undermine Fanpage.it’s investigative work.

Impact on Journalism:

  • Graphite granted full access to messages, location data, the microphone, and the camera.
  • Italian authorities acknowledged using Graphite for “national security” but denied targeting Cancellato, raising accountability concerns.

Risk Factors and Mitigation Strategies

The Graphite campaign highlights systemic vulnerabilities in mobile security.

Below are critical risk factors identified by researchers:

Risk FactorDescriptionImpact
Zero-click exploitNo user interaction required for infectionHigh
Targeted attacks on journalistsSpecific focus on media professionalsSevere privacy breach
Undetectable infectionNo visible indicators of compromiseProlonged surveillance risk
Delayed patchingOlder iOS versions remain vulnerableMedium
Government spyware useLack of oversight for mercenary toolsErosion of democratic safeguards

Mitigation Recommendations:

  • Immediate Updates: Install iOS 18.3.1 or later to patch CVE-2025-43200.
  • Enable Lockdown Mode: Restrict non-essential device features to reduce attack surfaces.
  • Threat Notifications: Heed warnings from Apple or WhatsApp and seek expert assistance.

The Graphite attacks underscore the dual threat of mercenary spyware and unregulated government surveillance.

While Apple’s patches mitigate immediate risks, the incident highlights urgent needs for transparency, accountability, and international regulations to protect journalists and civil society.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories