Workflow
Apple fixes new iPhone zero-day bug used in Paragon spyware hacks
AppleApple(US:AAPL) TechCrunchยท2025-06-12 17:06

Core Viewpoint - Two European journalists had their iPhones hacked using spyware developed by Paragon, and Apple has since addressed the vulnerability in a recent software update [1][3][5]. Group 1: Security Flaw and Response - Apple confirmed that the flaw exploited in the attacks was mitigated in the iOS 18.3.1 update released on February 10 [1][2]. - The updated advisory from Apple revealed a logic issue that could be exploited through maliciously crafted photos or videos shared via iCloud Links [3][2]. - The flaw was used in sophisticated attacks against specific individuals, including an Italian journalist and another prominent European journalist [3][6]. Group 2: Timeline and Notifications - The Paragon spyware scandal began in January when WhatsApp informed around 90 users, including journalists and human rights activists, about being targeted [5]. - In late April, Apple notified several iPhone users that they were targets of mercenary spyware, but did not disclose the spyware company involved [6]. - The Apple notification was sent to affected users in 100 countries, but it remains unclear if all recipients were targeted with Paragon's Graphite spyware [7].