Target Industry
CVE-2025-43200 is being used to target journalists and civil society members.
Overview
A zero-click exploit discovered in Apple’s Messages app has come to light. This vulnerability, tracked as CVE-2025-43200 (CVSS score 7.8), allows threat actors to infiltrate devices without user interaction. The vulnerability was fixed by Apple in a patch released in February 2025.
Impact
The impact of this vulnerability is significant, as it allows unauthorised access to sensitive data on targeted devices, potentially leading to severe financial, operational, and reputational damage for the victims. The exploitation of this vulnerability raises grave concerns about privacy and the safety of journalists, as it enables threat actors to monitor communications and gather intelligence without detection.
Affected Products
- iPhone XS and later
- iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
- macOS Sequoia
- Apple Watch Series 6 and later
- Apple TV HD and Apple TV 4K (all models)
Exploitation
The exploitation of CVE-2025-43200 involves sending a maliciously crafted photo or video via iCloud link, which triggers the logic flaw in the Messages app. This allows the Graphite spyware to be installed on the victim’s device without any interaction. The exploit is characterised as a zero-click attack, meaning it can be executed without the target’s knowledge.
Containment, Mitigations & Remediations
To mitigate the risks associated with this vulnerability, users are advised to update their devices to the latest iOS version. Additionally, implementing security best practices such as enabling two-factor authentication, using secure messaging applications, and regularly monitoring device activity can help reduce the risk of exploitation.
Threat Landscape
The vulnerability was exploited by Paragon’s Graphite spyware, which has been used in targeted attacks against journalists and human rights activists. The motivations behind these attacks often include political repression, and censorship.
Threat Group
The primary threat group associated with this vulnerability is Paragon, an Israeli surveillance firm known for developing mercenary spyware like Graphite. Paragon’s spyware has been linked to targeted attacks against journalists and human rights activists, utilising sophisticated tactics to exploit vulnerabilities in mobile operating systems. The group’s operations are characterised by their focus on high-value targets, including media professionals and activists.
Further Information













