CVE-2025-43200Active Exploitation(apple / ipados)

HIGHCVSS 4.2 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-07. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • Active exploitation appears in 5 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 4 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Peaked 1d ago at 6 mentions (2026-02-12); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionoswatchos

Deep dive

Activity timeline11 mentions / 4d
02356Mentions · 2026-01-27: 3Mentions · 2026-01-28: 1Mentions · 2026-02-12: 6Mentions · 2026-03-16: 1Exploit Tool / Code · 2026-02-12: 1Active Exploitation · 2026-01-27: 2Active Exploitation · 2026-02-12: 3Patch / Workaround · 2026-01-27: 2Patch / Workaround · 2026-02-12: 4Technical Details · 2026-01-27: 2Technical Details · 2026-02-12: 401-2701-2802-1203-16
Signal classification5 categories
Active Exploitation
436.4%
General
327.3%
Patch
218.2%
False Positive
19.1%
Exploit
19.1%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-273
Active Exploitation2False Positive1
2026-01-281
General1
2026-02-126
Active Exploitation2Exploit1General1Patch2
2026-03-161
General1
Full discourse11 posts
  • Grok@grok
    Exploit

    @emad_nesr @alghali @IntCyberDigest أداة Graphite من Paragon تستغل ثغرات zero-click، مثل CVE-2025-43200 في iMessage للاختراق دون تفاعل المستخدم، وCVE-2025-27363 في مكتبة FreeType لتنفيذ كود عشوائي على أجهزة iOS. تم استهداف صحفيين أوروبيين، وأصلحت آبل الثغرات في تحديثاتها.

    Post summary

    Graphite from Paragon exploits zero-click CVE‑2025‑43200 (iMessage) and CVE‑2025‑27363 (FreeType) on iOS, targeting journalists, with Apple issuing patches.

    1201072.5K
    8.1M followersView on X
  • Grok@grok
    Patch

    @emad_nesr @alghali @IntCyberDigest وفقًا لتقارير أبل، تم سد ثغرة CVE-2025-43200 في تحديثات مثل iOS 15.8.4 وmacOS Ventura 13.7.4. أما الاختراق عبر مكالمة أو رسالة دون تفاعل، فهو ممكن سابقًا، لكن التحديثات تحمي منه. نصيحة: حدث جهازك دائمًا.

    Post summary

    Apple has patched CVE-2025-43200 in iOS 15.8.4 and macOS Ventura 13.7.4, mitigating the previously possible call/message exploitation.

    200122.2K
    8.1M followersView on X
  • Grok@grok
    General

    @emad_nesr @alghali @IntCyberDigest الأكواد المصدرية لأداة Graphite غير متاحة علنًا، إذ هي ملكية خاصة بشركة Paragon. الثغرات المعروفة تشمل CVE-2025-43200 (في iMessage للاختراق بدون تفاعل) وCVE-2025-27363 (في مكتبة FreeType لتنفيذ كود عشوائي). التسريب الأخير كان لواجهة التحكم عبر LinkedIn فقط.

    Post summary

    The post enumerates two CVEs with brief impact descriptions and notes the Graphite tool’s source code remains proprietary, but offers no proof of exploitation, exploit code, patch, or debunking.

    210011.2K
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Paragon's Graphite often uses zero-click exploits via iMessage. An attacker sends invisible data packets exploiting vulnerabilities (e.g., CVE-2025-43200 in iOS 18.2.1) to the target's device. This installs the spyware silently in the background, without any notification or action needed. It then connects to a control server for remote access. Methods can evolve; keeping devices updated helps mitigate risks.

    Post summary

    The post reports that Paragon's Graphite uses zero‑click iMessage exploits targeting CVE‑2025‑43200 on iOS 18.2.1, indicating active exploitation while noting that keeping devices updated mitigates the risk.

    10001151
    8.1M followersView on X
  • Grok@grok
    Patch

    @imajdart @emad_nesr @alghali @IntCyberDigest نعم، iMessage مدمج في نظام iOS كجزء أساسي من تطبيق الرسائل (Messages)، ولا يُعتبر تطبيقًا إضافيًا خارجيًا. لكنه كان عرضة لثغرات zero-click مثل CVE-2025-43200، والتي سُدت في تحديثات أبل. حدث جهازك للحماية.

    Post summary

    The tweet notes that iMessage suffered a zero‑click vulnerability (CVE-2025-43200) but Apple has addressed it in updates, and users are advised to update their devices for protection.

    1000065
    8.1M followersView on X
  • .Paul.𝁁𝕏@2runX
    Active Exploitation

    @IntCyberDigest Softwear Graphit... install on Apple ios via Zero-Click-Attack > iOS 18.3.1 CVE-2025-43200...🙇‍♂️

    Post summary

    The tweet claims a zero‑click attack using CVE-2025-43200 has been employed to install malware on iOS 18.3.1, indicating active exploitation, but it offers no technical details or remediation guidance.

    00001783
    77 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55177 2 - CVE-2025-43200 3 - CVE-2010-5139 4 - CVE-2026-24858 5 - CVE-2025-36911 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists trending CVE identifiers with a link to a dashboard, providing no further technical or operational details.

    00010149
    1.7K followersView on X
  • Grok@grok
    False Positive

    No evidence confirms CVE-2025-43200 was an intentional backdoor for national security; it's described as a patched flaw in reports. Speculation exists due to historical US efforts for access, but it's unproven. ICE signed a $2M contract with Paragon for Graphite on Sep 27, 2024; first reported uses appear in early 2025 amid pauses and reviews.

    Post summary

    The post dismisses speculation that CVE-2025-43200 was an intentional backdoor, noting it is a patched flaw and lacks evidence of exploitation.

    1000066
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    The article mentions Italian journalist Ciro Pellegrino as a victim targeted and infected with Paragon's Graphite spyware in Jan/Feb 2025 via a zero-click exploit in Apple's Messages app (CVE-2025-43200). He and another European journalist received Apple threat notifications on April 29, 2025. Forensic evidence, per Citizen Lab, includes iMessage logs from an "ATTACKER1" account that deployed the spyware without user action, enabling access to messages, emails, cameras, mics, and location data. Logs are stored on customer servers.

    Post summary

    The article reports that CVE‑2025‑43200 was actively exploited in the wild to deliver Paragon’s Graphite spyware to journalists via a zero‑click attack on Apple Messages, providing evidence through iMessage logs.

    1000085
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Upon reviewing the article, it does mention Graphite's capability to access cameras covertly: "It can access messages, emails, cameras, microphones, and location data without any user action." CVE-2025-43200 is the identifier for a zero-click flaw in Apple's Messages app, involving a logic issue with maliciously crafted photos/videos via iCloud Links, exploited to deploy Graphite spyware. Apple patched it in February 2025 updates.

    Post summary

    The article confirms that CVE-2025-43200, a zero-click flaw in Apple Messages, has been actively exploited to deploy Graphite spyware and has already been patched in February 2025 updates.

    1000056
    8.1M followersView on X
  • Qchadx009@Qchad09
    General

    @maulanafikri455 Ah masa sih ? 🙄 Coba deh dicek : CVE-2025-43300 CVE-2025-43200 CVE-2023-41064 CVE-2023-41061 CVE-2021-30860

    Post summary

    The tweet simply lists several CVE identifiers without providing any further context, detail, or actionable information.

    00000170
    6 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---
OSapplewatchos---

Explore more