A Discreet Patch with Wide Security Implications
Apple’s ongoing security posture drew renewed attention after it quietly updated security notes for iOS 18.3.1 in June 2025, revealing it had earlier addressed a zero-day Messages app vulnerability exploited by the mercenary spyware “Graphite.” According to The Citizen Lab, this exploit was used in targeted attacks against European journalists, reaffirming growing industry concerns about mercenary spyware targeting civil society.
Timeline: Unannounced in February, Acknowledged in June
- iOS 18.3.1 shipped in February 2025 as a routine update, without disclosing a specific zero-day fix involved.
- In June 2025, Apple amended its public advisory, following research shared by Citizen Lab, to confirm an “extremely sophisticated attack against specific targeted individuals.”
The vulnerability leveraged a logic issue triggered via a carefully crafted iCloud link, allowing compromise of the Messaging app and subsequent device infiltration. Apple stated it was aware of reports
…