1 year ago
Apple Patched iPhone Flaw Used to Spy on Journalists
Apple quietly fixed a security problem in iPhones.
Hackers were using a sneaky trick involving photos and videos sent through iCloud links to spy on people's phones.
The fix was released in an update called iOS 18.3.1.
The attacks targeted journalists, allowing spyware called Graphite, made by a company named Paragon, to access their phones.
Citizen Lab found out about the problem first.
Apple didn't say anything about the fix until after Citizen Lab spoke up.
This incident highlights concerns about how spyware is used to watch people, particularly those in civil society.
Apple fixed a critical iPhone flaw in the iOS 18.3.1 update.
The flaw allowed spyware to be installed via malicious photos or videos sent through iCloud links.
The vulnerability was exploited using the Graphite spyware by Paragon.
The attacks targeted journalists and human rights defenders in Europe.
Apple acknowledged the flaw after Citizen Lab disclosed its findings.
- Who
- The flaw affected iPhone users, with attacks using Graphite spyware developed by Paragon.
- What
- Apple fixed a security flaw in iPhones that allowed spyware to be installed.
- Where
- The attacks targeted journalists in Europe.
- When
- The fix was released in the iOS 18.3.1 update in February.
- Why
- The flaw was exploited to allow targeted surveillance.
Apple
Citizen Lab
Disclosure Timing
Apple
Acknowledged the flaw after Citizen Lab disclosed the findings.
Citizen Lab
Did not publicly announce the fix until after the discovery.
Key facts
- Affected Device
- iPhone
- Vulnerability Type
- Messages app flaw
- Spyware Used
- Graphite
- Developer of Spyware
- Paragon
- Affected iOS Version
- iOS 18.2.1
- Fix Version
- iOS 18.3.1





