ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

iOS zero-click attacks used to deliver Graphite spyware (CVE-2025-43200)

highVulnerability exploited in the wildimportance 60CVE-2025-43200CVE-2025-24200

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24200
Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode

CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12.

Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product.

6.14% KEV
  • Apple iOS (iPhone) Versions prior to the fixed releases in each branch: iOS < 15.8.4, iOS < 16.7.11, and iOS < 18.3.1
  • Apple iPadOS (iPad) Versions prior to the fixed releases in each branch: iPadOS < 15.8.4, iPadOS < 16.7.11, iPadOS < 17.7.5, and iPadOS < 18.3.1
mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure)
CVE-2025-43200
Apple iCloud Link media-processing logic flaw exploited in targeted attacks

CVE-2025-43200 is a logic issue in Apple's operating systems that occurs when processing a maliciously crafted photo or video shared via an iCloud Link (CISA catalogs it as an unspecified vulnerability across Apple iOS, iPadOS, macOS, visionOS, and watchOS). An attacker must get a user to open the crafted shared-media link, and the CVSS 4.2 score indicates network delivery with high attack complexity, user interaction, and low-severity confidentiality and integrity impact, making the flaw most useful as a step in a larger attack chain. Apple states the issue was exploited in an "extremely sophisticated attack against specific targeted individuals," and related reporting links the February 2025 updates to actively exploited WebKit flaws and a Paragon spyware campaign against European journalists. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16; no public proof-of-concept is known, and EPSS estimates roughly a 1.0% chance of further exploitation in the next 30 days (62nd percentile). Anyone running iOS/iPadOS 15-18, macOS Ventura through Sequoia, visionOS, or watchOS on versions older than the listed fixes is affected.

Do: Update iOS to 15.8.4, 16.7.11, or 18.3.1; iPadOS to 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable; macOS to Sequoia 15.3.1, Sonoma 14.7.4, or Ventura 13.7.4; visionOS to 2.3.1; and watchOS to 11.3.1. Until patched, treat iCloud Links (shared photo/video links) from unknown senders with caution and use MDM to identify fleets still running pre-fix versions. US federal agencies must apply the vendor fixes per BOD 22-01 requirements given the KEV listing, and organizations at risk of targeted spyware should hunt for signs of post-exploitation on affected devices.

4.21% KEV
  • Apple iOS Versions prior to 15.8.4, 16.7.11, and 18.3.1 (fixed in iOS 15.8.4, 16.7.11, 18.3.1)
  • Apple iPadOS Versions prior to 15.8.4, 16.7.11, 17.7.5, and 18.3.1 (fixed in iPadOS 15.8.4, 16.7.11, 17.7.5, 18.3.1)
  • Apple macOS Versions prior to Ventura 13.7.4, Sonoma 14.7.4, and Sequoia 15.3.1 (fixed in those releases)
  • +2 more
masshundreds of millions to ~2 billion active Apple devices on affected OS versions
Full article690 words · extracted from helpnetsecurity.com · click to collapse

A zero-click attack leveraging a freshly disclosed Messages vulnerability (CVE-2025-43200) has infected the iPhones of two European journalists with Paragon’s Graphite mercenary spyware, Citizen Lab researchers have revealed on Thursday.

The attacks happened in January and early February 2025. “We believe that this infection would not have been visible to the target,” the researchers noted.

About CVE-2025-43200

CVE-2025-43200 is a logic issue triggered when the Apple smartphone processed a maliciously crafted photo or video shared via an iCloud Link. Apparently, the target did not have to open or view the booby-trapped media file delivered via an iMessage for the exploit to work.

Apple fixed the vulnerability in iOS 18.3.1, released on February 10, though it kept the vulnerability under wraps until Wednesday, June 11.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals,” the company says in the updated advisory.

No explanation has been provided for the company’s earlier reticence relating to CVE-2025-43200, which is surprising as, at the same time, it fixed another vulnerability flagged by Citizen Lab researcher Bill Marczak: CVE-2025-24200 was also used in an extremely sophisticated attack against specific targeted individuals and allowed attackers to disable USB Restricted Mode on a locked device. That flaw could apparently be exploited only if the attacker had physical access to the targeted vulnerable device.

What should you do?

Users who have upgraded to iOS 18.3.1 (and later iOS versions) are safe from this attack.

iPhone users concerned about being targeted by governments wielding mercenary spyware should consider enabling Lockdown Mode on iOS to minimize their attack surface.

There have been reports about Lockdown Mode blocking iOS spyware infections, though it’s unclear whether it can stymie this particular attack. High-risk users should also get in the habit of rebooting their device daily: spyware often does not have persistence capabilities and will be removed.

Users who suspect that their devices might have been compromised can turn to organizations such as Citizen Lab, Amnesty International, or Access Now for help. There are also various tools they can use to check whether they’ve been saddled with mercenary spyware.

An unidentified Paragon operator is behind the attacks

Citizen Lab found “forensic evidence confirming with high confidence that both a prominent European journalist (who requests anonymity), and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware.”

The two journalists received an Apple notification in late April 2025 warning that they had been targeted with “unspecified advanced spyware”, which spurred them to seek technical assistance from Citizen Lab, which has gained an international reputation for uncovering abuses involving mercenary spyware.

They say that the malware on both the infected devices contacted the same server, which Citizen Lab linked to a currently unidentified Paragon operator.

CVE-2025-43200 spyware

Source: Citizen Lab

Earlier this year, three other Italian individuals – human rights activists Luca Casarini and Dr. Giuseppe Caccia, and journalist Francesco Cancellato – have received a notification from WhatsApp notifying them that they’ve been targeted with Paragon’s spyware. In the first two cases, the researchers found evicence of a Graphite infection.

“While the recent Parliamentary Committee for the Security of the Republic (COPASIR) report confirms that Italy’s intelligence services used highly-invasive Graphite spyware to target activists, it sought to justify the use on national security grounds. It also denied the targeting of journalist Francesco Cancellato. This new finding that another Italian journalist has been targeted with Graphite spyware, raises more questions,” commented Elina Castillo Jiménez, Advocacy and Policy Advisor on targeted surveillance at Amnesty International.

In related news, Recorded Future analysts have documented the resurgence of activity of Predator mobile spyware, “despite public exposure, international sanctions, and policy interventions.”

UPDATE (June 16, 2025, 03:20 p.m. ET):

CISA has added CVE-2025-43200 to its Known Exploited Vulnerabilities catalog.

The agency described it as “an unspecified vulnerability” affecting Apple iOS, iPadOS, macOS, watchOS, and visionOS, which can be triggered by those operating systems “processing a maliciously crafted photo or video shared via an iCloud Link.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/06/13/ios-zero-click-attacks-used-to-deliver-graphite-spyware-cve-2025-43200/