ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-43300
Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O

CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed.

Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions.

10.022% KEV PoC
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion)
CVE-2025-55177
Incorrect Authorization in WhatsApp Linked-Device Sync Used in Targeted Spyware Attacks

CVE-2025-55177 is an incorrect authorization flaw (CWE-863) in how WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac validate linked device synchronization messages, allowing an unrelated user to trigger processing of content from an arbitrary URL on a target's device. An attacker can reach a vulnerable client through the messaging channel without normal authorization checks, causing the app to fetch or process attacker-chosen content. On its own the flaw carries only partial confidentiality and integrity impact (CVSS 5.4), but Meta assesses it was chained with an Apple OS vulnerability (CVE-2025-43300) in a sophisticated attack against specific, targeted users. Users running WhatsApp for iOS before 2.25.21.73, WhatsApp Business for iOS before 2.25.21.78, or WhatsApp for Mac before 2.25.21.78 are affected. The flaw was added to CISA's KEV catalog on 2025-09-02 amid reports of highly targeted zero-day attacks, though no public proof-of-concept is known and use in ransomware campaigns has not been reported.

Do: Update WhatsApp for iOS to v2.25.21.73 or later, WhatsApp Business for iOS to v2.25.21.78 or later, and WhatsApp for Mac to v2.25.21.78 or later. Also apply Apple's backported OS fix for CVE-2025-43300, since the two flaws were combined in the observed attack chain. Review and re-link WhatsApp companion devices if compromise is suspected; federal agencies must follow BOD 22-01 required-action deadlines per the KEV listing.

5.44% KEV
  • Meta Platforms WhatsApp for iOS all versions prior to 2.25.21.73
  • Meta Platforms WhatsApp Business for iOS all versions prior to 2.25.21.78
  • Meta Platforms WhatsApp for Mac all versions prior to 2.25.21.78
masshundreds of millions of users (WhatsApp's multi-billion user base includes a very large iOS/macOS install base)
Full article459 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 12, 2025

Apple has notified users in France of a spyware campaign targeting their devices, according to the Computer Emergency Response Team of France (CERT-FR).

The agency said the alerts were sent out on September 3, 2025, making it the fourth time this year that Apple has notified citizens in the county that at least one of the devices linked to their iCloud accounts may have been compromised as part of highly-targeted attacks.

The agency did not share further details on what triggered these alerts. Previous threat notifications were sent on March 5, April 29, and June 25. Apple has been sending these notices since November 2021.

"These complex attacks target individuals for their status or function: journalists, lawyers, activists, politicians, senior officials, members of steering committees of strategic sectors, etc," CERT-FR said.

The development comes less than a month after it emerged that a security flaw in WhatsApp (CVE-2025-55177, CVSS score: 5.4) was chained with an Apple iOS bug (CVE-2025-43300, CVSS score: 8.8) as part of zero-click attacks.

WhatsApp subsequently told The Hacker News that it had sent in-app threat notifications to less than 200 users who may have been targeted as part of the campaign. It's not known who, and which commercial spyware vendor, is behind the activity.

The disclosure also comes as Apple has introduced a security feature in the latest iPhone models called Memory Integrity Enforcement (MIE) to combat memory corruption vulnerabilities and make it harder for surveillance vendors, who typically rely on such zero-days for planting spyware on a target's phone.

In a report published this week, the Atlantic Council said the number of United States investors in spyware and surveillance technologies jumped from 11 in 2023 to 31 last year, surpassing other major investing countries such as Israel, Italy, and the United Kingdom.

Altogether, the study has flagged two holding companies, 55 individuals, 34 investors, eighteen partners, seven subsidiaries, 10 suppliers, and four vendors that established themselves in the last year in the spyware marketplace. This includes new spyware entities in Japan, Malaysia, and Panama, as well as vendors like Israel's Bindecy and Italy's SIO.

"The quantity of U.S.-based entities investing in the spyware market is three times greater than in the next three highest countries with the most investors," the report said, adding "56% of investors are incorporated in Israel, the United States, Italy, and the United Kingdom."

"Resellers and brokers now are key actors in the spyware market – comprising more sample market share than previously demonstrated – and oftentimes are under-observed and not readily addressed in current policy deliberations."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/09/apple-warns-french-users-of-fourth.html