Overview
- Forensic analysis by Citizen Lab confirmed that Italian journalist Ciro Pellegrino and an unnamed European reporter had their iPhones infected via a stealthy iMessage zero-click exploit.
- WhatsApp alerted about 90 users globally in January to potential Graphite targeting, but this is the first proof tying the spyware to confirmed infections on journalists’ devices.
- Apple’s iOS 18.3.1 update, released February 10, addressed CVE-2025-43200, the logic flaw in iMessage that powered the zero-click attack.
- Italy’s parliamentary committee COPASIR initially reported no evidence of journalist surveillance; the government later terminated its contract with Paragon Solutions in response to the revelations.
- Human rights advocates warn that deploying Graphite spyware against journalists and activists threatens privacy, freedom of expression and democratic accountability.