{"id":58812,"date":"2025-06-13T15:24:12","date_gmt":"2025-06-13T15:24:12","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/"},"modified":"2025-06-13T15:24:12","modified_gmt":"2025-06-13T15:24:12","slug":"apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/","title":{"rendered":"Apple fixes zero-click exploit underpinning Paragon spyware attacks"},"content":{"rendered":"<p>Apple has updated its iOS\/iPadOS 18.3.1 documentation, confirming it introduced fixes for the zero-click vulnerability used to infect journalists with Paragon&#8217;s Graphite spyware.<\/p>\n<p>The infections were confirmed when two journalists approached spyware researchers at The Citizen Lab after receiving notifications from Apple in April that they were targeted by spyware.<\/p>\n<p>The researchers looked under the hoods of the reporters&#8217; phones, confirming the same. Apple has since assigned the zero-day vulnerability CVE-2025-43200 (7.5), saying it was addressed with improved checks.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2021\/02\/27\/surveillance.jpg?x=174&amp;amp;y=115&amp;amp;crop=1\" width=\"174\" height=\"115\" alt=\"surveillance\"><\/p>\n<h2 title=\"Plus: Customer info stolen from 'parental control' software slinger SpyX; F-35 kill switch denied\">Paragon spyware deployed against journalists and activists, Citizen Lab claims<\/h2>\n<p><a href=\"https:\/\/www.theregister.com\/2025\/03\/21\/paragon_spyx_hacked\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>&#8220;A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link,&#8221; it said in the <a href=\"https:\/\/support.apple.com\/en-us\/122174\" rel=\"nofollow\">update<\/a>. &#8220;Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.&#8221;<\/p>\n<p>The details of the patch were added this week for the first time, despite version 18.3.1 and its documentation being released in February. The two journalists are thought to have been infected between January and February while running iOS version 18.2.1.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>The Citizen Lab claimed it had determined with &#8220;high confidence&#8221; that the attacks were carried out by the same group. One of the journalists involved wished to remain anonymous, while the other, a reporter for Italian newsite Fanpage.it, Ciro Pellegrino, was happy to be identified.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>Francesco Cancellato is Pellegrino&#8217;s editor at the online newspaper, which recently attracted attention for an undercover expos\u00e9 into the youth group of Italy&#8217;s rightwing Fratelli d&#8217;Italia. Cancellato said he also received a notification in January that he was targeted by spyware.&nbsp;<\/p>\n<p>However, this notification came from WhatsApp, said Cancellato, who was using an Android-based phone, and researchers weren&#8217;t able to confirm an infection due to the state of the device&#8217;s logs.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>&#8220;Following Mr Cancellato&#8217;s case, the identification of a second journalist at Fanpage.it targeted with Paragon suggests an effort to target this news organization,&#8221; <a href=\"https:\/\/citizenlab.ca\/2025\/06\/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted\/\" rel=\"nofollow\">said<\/a> The Citizen Labs&#8217; Bill Marczak and John Scott-Railton. &#8220;This appears to be a distinct cluster of cases that warrants further scrutiny.&#8221;<\/p>\n<p>The <a href=\"https:\/\/www.theregister.com\/2024\/10\/16\/whatsapp_privacy_concerns\/\">WhatsApp<\/a> notifications were sent to around 90 users \u2013 journalists and activists, including Cancellato \u2013 and Apple&#8217;s alerts in April spanned users across 100 countries.<\/p>\n<p>Zero-click attacks are not unheard of with spyware and have been seen in action, and later patched, from the likes of <a href=\"https:\/\/www.theregister.com\/2021\/09\/13\/apple_ios_macos_security_fixes\/\">NSO Group&#8217;s Pegasus spyware<\/a>.&nbsp;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aE3XuHx2VdKp3OqjLpqgawAAA1U&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>The Citizen Lab said it believes the latest Paragon infections were likely invisible to the victims, and mobile security experts at Jamf said Graphite is an exceptionally tricky strain of spyware.<\/p>\n<p>&#8220;What makes Graphite especially dangerous is its ability to operate covertly in memory, often leaving minimal artefacts on disk,&#8221; said Jamf&#8217;s senior security strategy manager Adam Boynton.&nbsp;<\/p>\n<p>&#8220;It is capable of creating system-level impersonations \u2013 for example, registering hidden iMessage accounts or spoofing security features \u2013 to conceal its presence from both the user and standard detection tools. These tactics make traditional mobile security models insufficient on their own.&#8221;<\/p>\n<p>The Italian government confirmed on Monday that it terminated its contract with the Israeli spyware slinger <a href=\"https:\/\/www.theregister.com\/2025\/03\/21\/paragon_spyx_hacked\/\">Paragon<\/a> in a bid to end the ongoing spyware scandal.&nbsp;<\/p>\n<p>The decision came after a parliamentary security committee (COPASIR) published <a href=\"https:\/\/documenti.camera.it\/_dati\/leg19\/lavori\/documentiparlamentari\/IndiceETesti\/034\/004\/INTERO.pdf\" rel=\"nofollow\">a report<\/a> [PDF, in Italian] acknowledging that seven individuals in Italy had been infected with Graphite.&nbsp;<\/p>\n<p>Among those seven was Cancellato, but like The Citizen Lab, it could not say with confidence who was behind the attack on the journalist.<\/p>\n<p>The Citizen Lab had previously confirmed infections with two other individuals named in the report, Luca Casarini and Dr Giuseppe Caccia \u2013 co-founders of human rights group Mediterranea Saving Humans.<\/p>\n<p>COPASIR&#8217;s report notes that the government opened contracts with Paragon in 2023 and 2024, and claims that intelligence services used the spyware sparingly.&nbsp;<\/p>\n<p>Only a small number of people were investigated, and were done so on grounds such as potential terrorism, immigration, spying, and other suspected crimes.<\/p>\n<p>Victims of spyware are advised to contact organizations such as Access Now, Amnesty International&#8217;s Security Lab, and The Citizen Lab, which have teams dedicated to helping individuals work through their cases.<\/p>\n<p>Boynton also suggested iPhone users keep updating their devices and turning on <a href=\"https:\/\/www.theregister.com\/2022\/07\/06\/apple_lockdown_mode\/\">Lockdown Mode<\/a>, which trades some fundamental iOS functionality in return for greater protection from spyware strains and the exploits that enable them. \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2025\/06\/13\/apple_fixes_zeroclick_exploit_underpinning\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zero-day potentially tied to around 100 suspected infections in 2025 and a spyware scandal on the continent Apple has updated its iOS\/iPadOS 18.3.1 documentation, confirming it introduced fixes for the zero-click vulnerability used to infect journalists with Paragon&#8217;s Graphite spyware.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":58813,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-58812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Apple fixes zero-click exploit underpinning Paragon spyware attacks 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple fixes zero-click exploit underpinning Paragon spyware attacks 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-13T15:24:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regmedia.co.uk\/2021\/02\/27\/surveillance.jpg?x=174&amp;amp;y=115&amp;amp;crop=1\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Apple fixes zero-click exploit underpinning Paragon spyware attacks\",\"datePublished\":\"2025-06-13T15:24:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/\"},\"wordCount\":726,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/\",\"name\":\"Apple fixes zero-click exploit underpinning Paragon spyware attacks 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg\",\"datePublished\":\"2025-06-13T15:24:12+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple fixes zero-click exploit underpinning Paragon spyware attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apple fixes zero-click exploit underpinning Paragon spyware attacks 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Apple fixes zero-click exploit underpinning Paragon spyware attacks 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-06-13T15:24:12+00:00","og_image":[{"url":"https:\/\/regmedia.co.uk\/2021\/02\/27\/surveillance.jpg?x=174&amp;amp;y=115&amp;amp;crop=1","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Apple fixes zero-click exploit underpinning Paragon spyware attacks","datePublished":"2025-06-13T15:24:12+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/"},"wordCount":726,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/","url":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/","name":"Apple fixes zero-click exploit underpinning Paragon spyware attacks 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg","datePublished":"2025-06-13T15:24:12+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/apple-fixes-zero-click-exploit-underpinning-paragon-spyware-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Apple fixes zero-click exploit underpinning Paragon spyware attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58812"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/58813"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}