Apple Warned Users in 110 Countries. No, Spyware Doesn’t Get In Through a Downloaded Game.

Apple has warned users in 110 countries. No, spyware doesn't get in through a downloaded game.


On Thursday, Apple sent out a new wave of threat notifications to users in 110 countries. It is the largest since the program was launched in 2021. The program now covers more than 150 countries. The alert appears in red on the lock screen, in Settings and on the account page. Apple also sends an email.

Une porte blindee couverte de douze verrous, une main gantee glisse une enveloppe par la fente a courrier et l enveloppe s ouvre seule a l interieur en liberant un oeil volant

The door is reinforced, with twelve locks. The problem is the mail slot.

And then everyone asks the same question. Someone asked me again yesterday: how does it get in? A downloaded game? A malicious app? Which one should be deleted?

Short answer: none. And that's precisely what makes it unsettling.

Nobody installed anything

These spyware tools are called mercenary spyware because they are rented out to governments. They don't arrive through the App Store. No game, no flashlight app, no attachment to open. They can get in through a message you haven't even read.

The mechanism is simple. When your phone receives a photo, a video or a call, it doesn't just display it. It analyzes the data to prepare a preview, identify the format and check that the file really matches what it claims to be. All of this happens automatically, before the slightest bubble even appears on the screen. If the code responsible for analyzing the file contains an error, a file designed to trigger that error may be enough. The attack is then launched. Without you.

Un centre de tri postal ou un colis s ouvre tout seul sur le tapis en liberant un oeil espion, pendant que le destinataire lit son journal dans la piece a cote

The package explodes at the sorting center. You're in the living room, your mailbox is empty and you didn't ask for anything.

This isn't a theory. The Citizen Lab, a University of Toronto laboratory renowned for its work on the subject, documented the case of two journalists. Their iPhones were infected with Graphite, the spyware developed by Paragon. The entry point was a vulnerability in the processing of a photo or video shared through an iCloud link. This vulnerability, identified as CVE-2025-43200, was exploited through iMessage accounts. No click was necessary. Apple fixed it in iOS 18.3.1.

Here we go again last February with CVE-2026-20700. This vulnerability caused memory corruption, meaning an error in the way a system component uses data in memory. Google's Threat Analysis Group discovered it. In its own bulletin, Apple described it as “exploited in an extremely sophisticated attack against specifically targeted individuals.” It was combined with two other vulnerabilities fixed in December. Three holes aligned for a single burglary.

Why it won't happen to you—and the price proves it

You're going to tell me: if my phone can be compromised without me doing anything, I'm doomed. No. The strongest argument isn't even technical. It's financial.

Graphique en barres des prix payes par un courtier en failles : 9 millions de dollars pour une chaine zero clic par SMS, 7 pour une faille iPhone, 5 pour iMessage, WhatsApp et Android, 3,5 pour Safari, 3 pour Chrome

Seven million for an entry point. That puts a damper on the urge to use it on just anyone.

These figures come from the public price list of an exploit broker, published in April 2024. A complete attack chain, meaning several exploits combined to take control of an iPhone by SMS and without any interaction, can sell for up to nine million dollars. This weapon is also disposable. As soon as Apple fixes the vulnerabilities, it is worthless. Nobody burns a seven-million-dollar round to read the messages of some guy who orders pizzas.

That is why Apple keeps repeating that these attacks are extremely rare and target specific people: journalists, lawyers, dissidents, diplomats, or executives. If you do not fall into any of these categories, your main risk is probably not there. It is somewhere else. And it is much stupider.

Where it really gets in, at your place

Here, on the other hand, apps and clicks do come into play. There are three main entry points, in order of frequency.

A gauche ce qu on imagine, un jeu pirate telecharge avec une tete de mort, a droite ce qui arrive vraiment, quelqu un qui tient le telephone deverrouille d un proche et un faux agent d assistance au telephone

On the right, the realistic version. No hooded hacker, just someone who knows your passcode.

The first is a configuration profile. It is a settings file that you install yourself. Originally intended for businesses and schools, it can redirect your traffic or add a certificate that allows certain connections to be controlled. A fake support call, a link, two buttons, and the profile is installed. Nobody hacked anything. You were simply convinced to do it yourself.

The second is two minutes alone with your unlocked phone. Stalkerware is often installed this way. No need for a seven-million-dollar exploit when someone knows their partner's passcode.

The third is your Apple ID. Here, there is no software to install. With your password, someone can access your iCloud backup, and therefore your messages and photos, from anywhere. It is the most discreet of the three entry points. And the one we always forget.

Ten minutes tonight, in Settings

Okay, let's get practical. Here are four places to check, in order. This applies to the whole family.

Réglages > Général > VPN et gestion de l'appareil
Réglages > [ton nom] > liste des appareils, tout en bas
Réglages > Temps d'écran
Réglages > Confidentialité et sécurité > Vérification de sécurité

In the first menu, there should be no profile that you did not install yourself. If this phone has never been configured by a school or a large company, the list should be empty. In the second, check that you recognize every device connected to your account. If not, disconnect it. The third may conceal restrictions installed by someone else. The fourth is designed for situations where you do not feel free to look through things calmly. It allows you to cut off all ongoing sharing at once.

And, obviously, install the updates. This is not advice from some old fogey. The vulnerabilities mentioned above remain dangerous as long as they have not been fixed on your device. The time between the publication of the patch and its installation is exactly the window of opportunity.

Lockdown Mode, and what it costs you

Lockdown Mode is the option Apple recommends to people who receive this notification. It has existed since iOS 16, and its results are frankly good. In March, Apple stated that it was aware of no successful attack of this kind against a device protected by this mode. Citizen Lab has also documented at least two cases in which it blocked an attack in progress.

This mode is not magic. It reduces the attack surface by disabling features, so you pay for it in convenience. It blocks most attachments in messages, except images. It disables complex web technologies, which can break some websites. It rejects 2G and 3G, Wi-Fi networks considered suspicious, wired connections with another device, and calls from unknown numbers. It also prevents the installation of a configuration profile.

In other words, it closes the mail slot. If you are a journalist, lawyer, or executive, enable it and live with its restrictions. If you are a plumber in Grez-Doiceau, you will mostly risk getting annoyed with your phone.

If you really receive the notification

One detail worth knowing, because this alert has become the best pretext for scams these days. A genuine Apple notification will never ask you to click a link, open a file, install an app or a profile. Nor will it ask for your password or a verification code, whether by email or phone. Never.

There is only one proper way to check the alert. Open account.apple.com yourself, then sign in. The notification should appear at the top of the page. If it isn't there, it's fake. If it is, Apple advises calling the Access Now NGO's emergency helpline, which provides this assistance free of charge.

What I think

There is a piece of good news hidden in this story, and no one really puts it that way. Taking control of an iPhone remotely requires several previously unknown vulnerabilities used in combination and costs several million dollars. That shows the device's security holds up remarkably well. We complain about Apple's walled garden, but that's also what makes this door so expensive to open.

The bad news is that an entire market makes money reselling these keys. Prices are displayed as though in a catalog of spare parts. And, for most targets, the only warning comes from a notification sent by the phone manufacturer. As a safety net, we've seen more reassuring ones.

So no, your nephew isn't going to install Pegasus on your phone with some lousy racing game. But tonight, check the list of profiles and devices connected to your account anyway. It takes two minutes. And that's where the real nasty surprises are hiding.

#iPhonesecurite#Privacyappleastuceslogiciels-espions
Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙