Apple disclosed multiple security fixes for supported iPhone and iPad devices, including CVE-2025-24200, which allowed a physical attacker to disable USB Restricted Mode on a locked device, and CVE-2025-43200, a logic flaw triggered by malicious photo or video content shared through an iCloud Link. Apple said both vulnerabilities may have been exploited in extremely sophisticated attacks against specific targeted individuals, and credited Citizen Lab researcher Bill Marczak for reporting the USB Restricted Mode issue.
Further reporting tied CVE-2025-43200 to a zero-click Messages exploitation chain used to install Paragon's Graphite spyware on the phones of several journalists in Europe. Apple urged users to update affected platforms, while a separate later advisory for iOS 26.0.1 and iPadOS 26.0.1 fixed CVE-2025-43400, an out-of-bounds write in font processing that could cause app crashes or memory corruption on supported iPhone and iPad models.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2025-09-29, Apple published a security notice for iOS 26.0.1 and iPadOS 26.0.1 disclosing CVE-2025-43400, an out-of-bounds write that could be triggered by processing a maliciously crafted font. Apple said the issue could cause unexpected app termination or corrupt process memory and was fixed with improved bounds checking.
CSIRT.SK reported that, according to Citizen Lab, CVE-2025-43200 was exploited to install Paragon's Graphite spyware on the mobile devices of several journalists in Europe. The same reporting described the flaw as a zero-click remote code execution issue in Messages involving photo and video content shared through iCloud links.
On 2025-06-12, Apple published a security notice documenting the February fixes and the newly added CVE-2025-43200 entry. The notice credited Bill Marczak of Citizen Lab for reporting CVE-2025-24200 and described both vulnerabilities as potentially exploited against specific targeted individuals.
On 2025-06-11, Apple updated its advisory to include CVE-2025-43200, a logic issue triggered by a maliciously crafted photo or video shared through an iCloud Link. Apple said this second flaw may also have been exploited in sophisticated targeted attacks.
On 2025-02-10, Apple released iOS 18.3.1 and iPadOS 18.3.1 to address CVE-2025-24200, which could let a physical attacker disable USB Restricted Mode on a locked device. Apple said the flaw may have been exploited in extremely sophisticated attacks against specific targeted individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
support.apple.com
Open sourcecsirt.sk
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.