Cyber Incident Briefs
Paragon Graphite on iPhone: Lessons From a Reported Zero-Click Spyware Case
Review Citizen Lab’s reported Paragon Graphite iPhone findings, Apple’s CVE-2025-43200 advisory, the evidence limits, and lessons for high-risk users.

In June 2025, Citizen Lab published what it described as the first forensic confirmation of Paragon’s iOS mercenary spyware, known as Graphite. The researchers reported high-confidence evidence that two journalists had been targeted and that one iPhone running iOS 18.2.1 had been compromised in January or early February 2025. Apple separately documented CVE-2025-43200, a vulnerability involving maliciously crafted photos or videos shared through an iCloud Link, and said it may have been exploited in an extremely sophisticated attack against specifically targeted individuals.
This Paragon Graphite iPhone incident brief summarizes those reported findings at the level the sources support. OC Security Audit did not examine the devices and is not independently attributing activity to Paragon or any government customer.
Incident brief
The Citizen Lab report states that its researchers examined devices after Apple sent threat notifications. They concluded with high confidence that two journalists were targeted and one device was compromised by Paragon’s Graphite spyware. Citizen Lab reported that the compromise required no user interaction and placed the activity in January or early February 2025.
Citizen Lab also said Apple confirmed to the researchers that the zero-click vector had been mitigated in iOS 18.3.1. Apple’s iOS 18.3.1 security advisory, released February 10, 2025, later included CVE-2025-43200. Apple described a logic issue involving iCloud Link processing and stated that it may have been exploited in an extremely sophisticated attack against specific targeted individuals.
The two sources align on a targeted iPhone issue and the mitigating release, but they play different roles: Citizen Lab provides the forensic analysis and attribution; Apple provides the product security advisory. Neither source should be expanded into a claim that all iCloud Links, all journalists, or all iPhones were compromised.

Why the zero-click detail matters
Many awareness programs assume that the user must click, install, approve, or enter credentials before a phone can be compromised. Citizen Lab’s finding describes a zero-click path: the reported target did not need to interact with the delivery. This does not make user education irrelevant, but it changes the control balance.
For exceptional-risk users, current software, Apple threat-notification response, Lockdown Mode, specialist support, and account/session monitoring become more important. An organization cannot rely only on teaching the user to recognize a suspicious message.
Confirmed, reported, and unknown
| Evidence level | What can be said |
|---|---|
| Apple advisory | CVE-2025-43200 affected malicious iCloud Link media processing; Apple said it may have been exploited in extremely sophisticated targeted attacks |
| Citizen Lab finding | Citizen Lab reported high-confidence targeting of two journalists, one compromise, a zero-click path, and attribution to Graphite |
| OC Security Audit position | This article reports and analyzes those sources; it is not an independent forensic or attribution finding |
| Not established here | The identity of every operator or customer, all targets, full data impact, and every version or delivery path used outside the reported cases |
Keeping these categories separate reduces defamation and misinformation risk and gives incident leaders a model for their own communications.
Defensive lessons for organizations
Treat threat notifications as an escalation event
Apple says its threat notifications are intended for users individually targeted by mercenary spyware. An authentic notice should reach a predefined security, safety, legal, and executive process. Preserve it, verify through account.apple.com, and do not ask the user to click a message link or share a verification code.
Accelerate updates for high-risk people
The reported device was running iOS 18.2.1; Apple and Citizen Lab tied mitigation to iOS 18.3.1. This reinforces the need for an accelerated update channel, direct assistance, and proof of installation for high-risk roles. Current release status must be checked against Apple’s security releases page, not frozen at the historical version in this case.
Prepare for evidence before erasing
Citizen Lab’s conclusion depended on forensic artifacts. A reflexive factory reset after every warning may remove evidence needed to establish targeting or scope. The response plan should authorize a specialist preservation decision quickly while protecting the person’s immediate safety.
Reduce attack surface beyond clicking behavior
Apple’s Lockdown Mode guidance describes restrictions intended for people at exceptional risk. The organization should also review cloud sessions, administrative access, recovery paths, primary email, assistants, and other Apple devices associated with the user.
What ordinary iPhone security apps can and cannot do
An App Store application can inspect the data and interfaces Apple permits. It cannot freely examine every protected process, another app’s private data, or the full operating system. Network and configuration tools may still provide useful signals, but “no alert” is not proof that sophisticated spyware is absent.
The iPhone Security Review Checklist can identify visible profiles, privacy settings, and account concerns. Use it for initial review, not as a Graphite detection or forensic conclusion.
Executive questions after this case
- Which employees could receive a mercenary-spyware notification, and who supports them?
- Can high-risk users update rapidly during travel or a sensitive engagement?
- Has Lockdown Mode been evaluated and tested before an incident?
- Can responders preserve a phone and maintain secure replacement communications?
- Do internal statements distinguish targeting, attempted exploitation, compromise, and impact?
- Who approves public attribution, and what corroboration is required?
- Are primary sources and correction dates retained with the incident record?
Sources
Build evidence-aware mobile incident readiness
OC Security Audit can help organizations plan high-risk-user protection, evidence preservation, identity review, and careful executive communication. Contact OC Security Audit and learn about Ali Hassani, CISO, whose work combines cybersecurity, infrastructure, compliance, and leadership experience.
Update and correction history
- August 2026: Apple source links were revalidated and updated to current official canonical destinations; the surrounding analysis and conclusions were unchanged.
- July 2026: Initial incident brief prepared from Citizen Lab and Apple sources available through July 31, 2026.