Overview
- France’s CERT-FR says Apple sent a new wave of threat notifications on September 3, following earlier rounds on March 5, April 29, and June 25.
- Receiving the alert means at least one device tied to the recipient’s iCloud account was targeted and may be compromised, with notifications delivered via iMessage, email, and account.apple.com.
- CERT-FR urges recipients to contact the agency, preserve the original Apple email, and avoid resetting, updating, or otherwise altering devices to protect evidence.
- The campaigns use highly sophisticated techniques including zero-day and zero-click exploits, with recent attacks chaining iOS CVE-2025-43300 and WhatsApp CVE-2025-55177; WhatsApp sent in-app notices to fewer than 200 users.
- Apple advises updates, Lockdown/Isolation Mode, and expert help, declines to attribute the activity, and has added Memory Integrity Enforcement to the latest iPhone models to harden against memory-corruption exploits.