Target Industry

CVE-2025-43200 is being used to target journalists and civil society members. 

Overview

A zero-click exploit discovered in Apple’s Messages app has come to light. This vulnerability, tracked as CVE-2025-43200 (CVSS score 7.8), allows threat actors to infiltrate devices without user interaction. The vulnerability was fixed by Apple in a patch released in February 2025.

Impact

The impact of this vulnerability is significant, as it allows unauthorised access to sensitive data on targeted devices, potentially leading to severe financial, operational, and reputational damage for the victims. The exploitation of this vulnerability raises grave concerns about privacy and the safety of journalists, as it enables threat actors to monitor communications and gather intelligence without detection. 

Affected Products

  • iPhone XS and later
  • iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
  • macOS Sequoia
  • Apple Watch Series 6 and later
  • Apple TV HD and Apple TV 4K (all models)

Exploitation

The exploitation of CVE-2025-43200 involves sending a maliciously crafted photo or video via iCloud link, which triggers the logic flaw in the Messages app. This allows the Graphite spyware to be installed on the victim’s device without any interaction. The exploit is characterised as a zero-click attack, meaning it can be executed without the target’s knowledge.

Containment, Mitigations & Remediations

To mitigate the risks associated with this vulnerability, users are advised to update their devices to the latest iOS version. Additionally, implementing security best practices such as enabling two-factor authentication, using secure messaging applications, and regularly monitoring device activity can help reduce the risk of exploitation.  

Threat Landscape

The vulnerability was exploited by Paragon’s Graphite spyware, which has been used in targeted attacks against journalists and human rights activists. The motivations behind these attacks often include political repression, and censorship.

Threat Group

The primary threat group associated with this vulnerability is Paragon, an Israeli surveillance firm known for developing mercenary spyware like Graphite. Paragon’s spyware has been linked to targeted attacks against journalists and human rights activists, utilising sophisticated tactics to exploit vulnerabilities in mobile operating systems. The group’s operations are characterised by their focus on high-value targets, including media professionals and activists. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content