Forensic investigation has confirmed the use of Paragon's Graphite spyware platform in zero-click attacks that targeted Apple iOS devices of at least two journalists in Europe. Researchers at Citizen Lab say that the victims were a prominent European journalists who requested anonimity and Ciro Pellegrino, a journalist at Italian publication Fanpage.it. “Our analysis finds forensic evidence confirming with high confidence that both a prominent European journalist (who requests anonymity), and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware,” reports Citizen Lab. The attacks occurred in early 2025, and Apple sent a notification to the two victims on April 29 informing that they had been targeted by “advanced spyware.” The threat actor used Paragon's Graphite spyware platform to target the victims' iPhone devices running iOS 18.2.1 and exploit CVE-2025-43200, which was a zero-day vulnerability at the time. Apple describes the flaw as “a logic issue that existed when processing a maliciously crafted photo or video shared via an iCloud Link.” The vendor addressed the vulnerability in the next iOS release, 18.3.1, on February 10, by adding improved checks. However, the CVE identifier was added earlier today to the security bulletin . BleepingComputer has reached out to Apple to clarify the date of fixing the vulnerability but have not received a response at publishing time. According to Citizen Lab's analysis, Graphite’s delivery vector...
Graphite spyware used in Apple iOS zero-click attacks on journalists
BleepingComputer
·Bill Toulas
·Published Jun 12, 2025
·Updated
Affected Software
1 affected component
Apple iPhone=iOS 18.2.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the use of Graphite spyware in zero-click attacks on Apple iOS devices targeting journalists.
2
What security implications are discussed in the article?
The article highlights the serious threat posed by zero-click exploits that can compromise devices without user interaction.
3
What products or software are affected by the spyware?
The affected software mentioned is Apple's iOS, specifically version 18.2.1.
4
Who are the primary victims of these attacks?
The primary victims of these attacks are journalists based in Europe.
5
What organization conducted the forensic investigation into these attacks?
The forensic investigation was conducted by researchers at Citizen Lab.