Apple Quietly Fixed Zero-Day Exploit Used in Paragon Spyware Attack

Apple today quietly updated the list of security fixes that were introduced in iOS 18.3.1, noting a previously undisclosed fix for a zero-day vulnerability affecting the Messages app.

bug security vulnerability issue fix larry
Apple acknowledged the fix after security researchers from The Citizen Lab shared details on the flaw, which had been used to target two European journalists. The Messages vulnerability was exploited with the "Graphite" mercenary spyware created by Paragon. Paragon's spyware has been used in targeted attacks against journalists and human rights activists across multiple platforms.

According to Apple, a maliciously crafted photo or video shared through an iCloud link led to a logic issue that allowed for the infiltration of targeted devices. Apple's release notes say that it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."

Apple confirmed to The Citizen Lab that it fixed the vulnerability back when iOS 18.3.1 was released in February, but it is not clear why Apple did not disclose it before today.

Note: Due to the political or social nature of the discussion regarding this topic, the discussion thread is located in our Political News forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Popular Stories

iphone air thickness

Apple Said to Cut iPhone Air Production Amid Underwhelming Sales

Friday October 17, 2025 8:29 am PDT by
Apple plans to cut production of the iPhone Air amid underwhelming sales performance, Japan's Mizuho Securities believes (via The Elec). The Japanese investment banking and securities firm claims that the iPhone 17 Pro and iPhone 17 Pro Max are seeing higher sales than their predecessors during the same period last year, while the standard iPhone 17 is a major success, performing...
iOS 26 Feature

iOS 26.1 to iOS 26.4 Will Add These New Features to Your iPhone

Saturday October 18, 2025 11:00 am PDT by
iOS 26 was released last month, but the software train never stops, and iOS 26.1 beta testing is already underway. So far, iOS 26.1 makes both Apple Intelligence and Live Translation on compatible AirPods available in additional languages, and it includes some other minor changes across the Apple Music, Calendar, Photos, Clock, and Safari apps. More features and changes will follow in future ...
iOS 26

iOS 26.0.2 Update for iPhones Coming Soon

Friday October 17, 2025 7:35 am PDT by
Apple's software engineers continue to internally test iOS 26.0.2, according to MacRumors logs, which have been a reliable indicator of upcoming iOS versions. iOS 26.0.2 will be a minor update that addresses bugs and/or security vulnerabilities, but we do not know any specific details yet. The update will likely be released by the end of next week. Last month, Apple released iOS 26.0.1,...
HomePod mini and Apple TV

Apple's Next Rumored Products: New HomePod Mini, Apple TV, and More

Thursday October 16, 2025 9:13 am PDT by
Apple on Wednesday updated the 14-inch MacBook Pro, iPad Pro, and Vision Pro with its next-generation M5 chip, but previous rumors have indicated that the company still plans to announce at least a few additional products before the end of the year. The following Apple products have at one point been rumored to be updated in 2025, although it is unclear if the timeframe for any of them has...
14 inch MacBook Pro Keyboard

New 14-Inch MacBook Pro Has Two Key Upgrades Beyond the M5 Chip

Thursday October 16, 2025 8:31 am PDT by
Apple on Wednesday updated the 14-inch MacBook Pro base model with an M5 chip, and there are two key storage-related upgrades beyond that chip bump. First, Apple says the new 14-inch MacBook Pro offers up to 2× faster SSD performance than the equivalent previous-generation model, so read and write speeds should get a significant boost. Apple says it is using "the latest storage technology," ...
Apple iPad Pro hero M5

New iPad Pro Has Six Key Upgrades Beyond M5 Chip

Saturday October 18, 2025 10:57 am PDT by
While the new iPad Pro's headline feature is the M5 chip, the device has some other changes, including N1 and C1X chips, faster storage speeds, and more. With the M5 chip, the new iPad Pro has up to a 20% faster CPU and up to a 40% faster GPU compared to the previous model with the M4 chip, according to Geekbench 6 results. Keep in mind that 256GB and 512GB configurations have a 9-core CPU,...
iPhone Siri Glow

Some Apple Employees Have 'Concerns' About iOS 26.4's Revamped Siri

Sunday October 19, 2025 7:39 am PDT by
iOS 26.4 is expected to introduce a revamped version of Siri powered by Apple Intelligence, but not everyone is satisfied with how well it works. In his Power On newsletter today, Bloomberg's Mark Gurman said some of Apple's software engineers have "concerns" about the overhauled Siri's performance. However, he did not provide any specific details about the shortcomings. iOS 26.4 will...
m4 macbook air blue

M5 MacBook Air Coming Spring 2026 With M5 Mac Studio and Mac Mini in Development

Thursday October 16, 2025 3:57 pm PDT by
Apple plans to launch MacBook Air models equipped with the new M5 chip in spring 2026, according to Bloomberg's Mark Gurman. Apple is also working on M5 Pro and M5 Max MacBook Pro models that will come early in the year. Neither the MacBook Pro models nor the MacBook Air models are expected to get design changes, with Apple focusing on simple chip upgrades. In the case of the MacBook Pro, a m...
14 inch MacBook Pro Keyboard

M5 Chip Achieves Impressive Feat in 14-Inch MacBook Pro Speed Test

Friday October 17, 2025 7:10 am PDT by
The first alleged benchmark result for the M5 chip in the new 14-inch MacBook Pro has surfaced, allowing for some performance comparisons. Based on a single unconfirmed result uploaded to the Geekbench 6 database today, the M5 chip has pulled off an impressive feat. Specifically, the chip achieved a score of 4,263 for single-core CPU performance, which is the highest single-core score that...

Top Rated Comments

aloysiusfreeman Avatar
19 weeks ago
Great to see a US-backed company working on surveilling journalists and activists.

Can't wait to see the feds using this on us
Score: 6 Votes (Like | Disagree)
russell_314 Avatar
19 weeks ago

Great to see a US-backed company working on surveilling journalists and activists.

Can't wait to see the feds using this on us
Nothing new. The US government has been using private companies and NGO’s for years or likely decades to do their dirty work. The US government might not be allowed to censor or spy on citizens, but they can have a private organization do it for them.
Score: 6 Votes (Like | Disagree)
Plutonius Avatar
19 weeks ago
It's good to see that Apple addressed this exploit. Unfortunately, the next exploit will probably hit soon if it already hasn't :(.
Score: 5 Votes (Like | Disagree)
ThailandToo Avatar
18 weeks ago

Nothing new. The US government has been using private companies and NGO’s for years or likely decades to do their dirty work. The US government might not be allowed to censor or spy on citizens, but they can have a private organization do it for them.
Just like Apple. I am sure Snowden didn’t make everything up. I also believe the Bloomberg report about China installing chips on Apple’s servers was probably legitimate; why would Apple admit to it? Their whole business model is made in China with slave labor. Funny thing is people believe the marketing hype about Apple caring about our privacy - AAPL cares about the illusion of our privacy.
Score: 3 Votes (Like | Disagree)
Mousse Avatar
18 weeks ago

Much of the above seems like a gross generalization. Who determines a fair and equitable salary for employees? Certainly not MR posters.
Not who, but what. Productivity determines what is fair and equitable.
apple zero day exploit fix ios 18 3 1 image
apple zero day exploit fix ios 18 3 1 image
As you can see, compensation hasn't matched productivity since the 70's.
Score: 3 Votes (Like | Disagree)
russell_314 Avatar
18 weeks ago

More likely trying to not create a new news cycle about the original exploit. They fixed the issue but left it out of the release notes initially, because of course people are going to be looking at those release notes when an update is brand new. Then once most people have the update and interest has died down, update them so it's on record in case anyone says "there was this exploit and Apple never patched it".
Every time I’ve seen Apple release updates for security patches they never describe the actual security flaw. So I guess Apple always “quietly” updates their security vulnerabilities ?




Just like Apple. I am sure Snowden didn’t make everything up. I also believe the Bloomberg report about China installing chips on Apple’s servers was probably legitimate; why would Apple admit to it?
You’re absolutely right it would not benefit Apple to admit they had a security breach, but if they know customer data has been breached they have to tell people. This is written into law from my understanding.



Their whole business model is made in China with slave labor. Funny thing is people believe the marketing hype about Apple caring about our privacy - AAPL cares about the illusion of our privacy.
You just described every product you buy in 2025. At least products sold in the USA. Everything you’re wearing was probably made the way you describe. Most of your gadgets in your home were made that way. Likely just about everything you own was made that way. Unfortunately that’s a terrible fact of how things are going now, but it’s not exclusive to Apple. It’s either made in China or a similar country with similar working conditions. In some cases products are made outside of China because China is too strict about working conditions compared to those countries.
Score: 3 Votes (Like | Disagree)