European Journalists Targeted by Paragon Spyware, Citizen Lab Confirms
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-43200 | Apple iCloud Link media-processing logic flaw exploited in targeted attacks CVE-2025-43200 is a logic issue in Apple's operating systems that occurs when processing a maliciously crafted photo or video shared via an iCloud Link (CISA catalogs it as an unspecified vulnerability across Apple iOS, iPadOS, macOS, visionOS, and watchOS). An attacker must get a user to open the crafted shared-media link, and the CVSS 4.2 score indicates network delivery with high attack complexity, user interaction, and low-severity confidentiality and integrity impact, making the flaw most useful as a step in a larger attack chain. Apple states the issue was exploited in an "extremely sophisticated attack against specific targeted individuals," and related reporting links the February 2025 updates to actively exploited WebKit flaws and a Paragon spyware campaign against European journalists. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16; no public proof-of-concept is known, and EPSS estimates roughly a 1.0% chance of further exploitation in the next 30 days (62nd percentile). Anyone running iOS/iPadOS 15-18, macOS Ventura through Sequoia, visionOS, or watchOS on versions older than the listed fixes is affected. Do: Update iOS to 15.8.4, 16.7.11, or 18.3.1; iPadOS to 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable; macOS to Sequoia 15.3.1, Sonoma 14.7.4, or Ventura 13.7.4; visionOS to 2.3.1; and watchOS to 11.3.1. Until patched, treat iCloud Links (shared photo/video links) from unknown senders with caution and use MDM to identify fleets still running pre-fix versions. US federal agencies must apply the vendor fixes per BOD 22-01 requirements given the KEV listing, and organizations at risk of targeted spyware should hunt for signs of post-exploitation on affected devices. | 4.2 | 1% | KEV |
| masshundreds of millions to ~2 billion active Apple devices on affected OS versions |
Full article625 words · extracted from infosecurity-magazine.com · click to collapse
Written by
Researchers from the Citizen Lab have revealed the first forensic evidence that the iPhones of at least two European journalists were infected with Graphite, a piece of spyware developed by the Israeli company Paragon Solutions.
In a June 12 post, Bill Marczak and John Scott-Railton, two researchers at the University of Toronto’s digital forensic research center, stated that they had found forensic evidence confirming, with high confidence, that the devices of both an anonymous European journalist and Italian journalist Ciro Pellegrino had Graphite installed.
“We identify an indicator linking both cases to the same Paragon operator,” the researchers added.
Apple had confirmed to the researchers that the zero-click attack deployed in these cases exploited a critical vulnerability (CVSSv3 score of 9.8) in iOS. The flaw, tracked as CVE-2025-43200, stems from a logic issue when processing a maliciously crafted photo or video shared via an iCloud Link. It was mitigated in the latest iOS version, 18.3.1.
Confirmed Graphite Zero-Click Infection Attempts
The Citizen Lab’s forensic analysis followed an alert from Apple on April 29, 2025, which the tech giant said it had detected a select group of iOS users had been targeted with advanced spyware.
Two journalists decided to hand over their devices to the researchers, who found that one of the anonymous European journalist’s devices was compromised with Paragon’s Graphite spyware in January and early February 2025 while running iOS 18.2.1.
“We attribute the compromise to Graphite with high confidence because logs on the device indicated that it made a series of requests to a server that, during the same time period, matched our published Fingerprint P1. We linked this fingerprint to Paragon’s Graphite spyware with high confidence,” the researchers say.
Pellegrino allowed the researchers to analyze his devices after receiving the Apple notification on April 29. “Our analysis of the device’s logs revealed the presence of the same iMessage account used to target the [anonymous European] journalist, which we associate with a Graphite zero-click infection attempt,” added the researchers.

A third journalist and colleague of Pellegrino, Fanpage.it editor Francesco Cancellato, was notified in January 2025 by WhatsApp that he was targeted with Paragon’s Graphite spyware.
The Citizen Lab has conducted a forensic analysis of Cancellato’s Android device but did not find any confirmation of a successful infection.
The Citizen Lab sent a summary of its findings to Paragon on June 10, 2025, and gave them the chance to respond, but had not received a reply by the time of publication.
Italy Cuts Ties with Paragon
These new findings come a few days after the Italian government's parliamentary committee, COPASIR, published a report on June 5, 2025, confirming that the Italian government had used Paragon's Graphite spyware against two individuals, Luca Casarini and Giuseppe "Beppe" Caccia.
According to The Citizen Lab, subsequent developments revealed that Paragon had offered to assist in investigating a third individual, Mr. Cancellato, who had been targeted with the same spyware.
However, their offer was rejected by the Italian government on June 9, 2025, as reported by Haaretz. Paragon also suggested that they had unilaterally terminated Italy’s contracts.
The Italian Department of Security Intelligence (DIS) cited national security concerns as the reason for rejecting Paragon's offer, stating that it would compromise their reputation among international peer services, and denied that they had unilaterally terminated their contract with Paragon.
The COPASIR committee, however, clarified that it had chosen not to proceed with Paragon's offer, opting instead to directly access Paragon's databases and expressed its willingness to declassify Paragon's testimony to the committee.
Read now: How to Mitigate Spyware Risks and Secure Your Business Secrets
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/european-journalists-paragon/