{"id":1921,"date":"2025-03-20T10:03:00","date_gmt":"2025-03-20T10:03:00","guid":{"rendered":"https:\/\/netguide.io\/news\/2025\/03\/20\/whatsapp-fixes-zero-click-flaw-paragon-spyware\/"},"modified":"2026-08-26T00:48:49","modified_gmt":"2026-08-26T00:48:49","slug":"whatsapp-fixes-zero-click-flaw-paragon-spyware","status":"publish","type":"post","link":"https:\/\/netguide.io\/news\/en\/2025\/03\/20\/whatsapp-fixes-zero-click-flaw-paragon-spyware\/","title":{"rendered":"WhatsApp Fixes Zero-Click Security Flaw After Paragon Spyware Attacks"},"content":{"rendered":"<div id=\"netgu-1211015412\" class=\"netgu-before-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"3494115342\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p class=\"wp-block-paragraph\">WhatsApp recently fixed a serious security vulnerability that was exploited by cybercriminals to install the Graphite spyware from the Israeli company Paragon onto the devices of targeted individuals. This zero-click vulnerability was used in an attack that targeted journalists and members of civil society, and it was uncovered by the security researchers at the University of Toronto&#8217;s Citizen Lab.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attack leveraged a zero-day vulnerability that allowed the attackers to install the spyware on victims&#8217; devices without them having to perform a single click \u2013 hence the term \u201czero-click.\u201d WhatsApp responded by fixing the issue in late 2024, without requiring an update from end users. It was decided not to assign a CVE ID (Common Vulnerabilities and Exposures) to this flaw, after the company had reviewed the relevant guidelines of the MITRE CVE system as well as its own internal standards.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Targeted Attacks on Journalists and Activists<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The attack affected around 90 Android users from more than two dozen countries, including journalists and activists from Italy. The attackers first added their victims to a WhatsApp group and then sent a specially crafted PDF document. The PDF triggered the exploit and made it possible to install the Graphite spyware in the background. This spyware could then also compromise other apps on the affected devices and give the attackers access to the victims&#8217; private communication channels.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WhatsApp contacted all affected users directly and informed them about the possible compromise of their devices. The WhatsApp spokesperson emphasized that this is yet another example of why companies that distribute spyware must be held accountable for their illegal activities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Graphite Spyware and Its Background<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Graphite spyware was developed by Paragon Solutions, an Israeli company, and is used for the targeted surveillance of communication platforms. Unlike many other spyware companies, Paragon claims to sell its products exclusively to democratic countries and their law enforcement agencies. Nevertheless, Paragon has increasingly been linked to reports that its technologies could also be deployed in authoritarian contexts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Through an analysis of Paragon&#8217;s server infrastructure, Citizen Lab was able to find important clues about the origin and scope of the espionage activities. Among other things, it was found that several digital fingerprints and certificates pointed to connections with various governments, including Australia, Canada, Denmark, Israel, and Singapore.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Paragon and Its Ties to Governments<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Paragon was founded in 2019 by Ehud Barak, the former Israeli prime minister, and Ehud Schneorson, the former commander of Israel&#8217;s Unit 8200. In December 2024, the company was acquired by the Florida-based investment group AE Industrial Partners for 900 million US dollars. According to reports, Paragon had already partnered with the US Drug Enforcement Administration (DEA) in 2022, and in 2024 it emerged that the company had signed a contract worth 2 million dollars with the US Immigration and Customs Enforcement agency (ICE).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WhatsApp Responds with Legal Action<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">WhatsApp stated that it had sent Paragon a \u201ccease-and-desist letter\u201d and was considering taking legal action against the company. This was said to be another step in the fight against companies that develop technologies which undermine data protection and the rights of individuals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhatsApp has stopped a Paragon spying campaign that targeted a number of users, including journalists and members of civil society. We have reached out directly to the people affected,\u201d a WhatsApp spokesperson said. \u201cThis is the latest example of why companies that produce spyware must be held accountable for their illegal actions. WhatsApp will continue to protect people&#8217;s privacy and their right to communicate securely.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This incident once again highlights the threats posed by commercial surveillance software such as Paragon, and the need to ensure the protection of users&#8217; privacy worldwide. By reacting quickly to fix the vulnerability and warn the affected users, WhatsApp has taken an important step in combating cyberattacks and preventing data espionage. Nevertheless, the challenge remains to stop the illegal trade in such technologies and to hold those responsible accountable.<\/p>\n<div id=\"netgu-1174563808\" class=\"netgu-after-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"4559785002\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>WhatsApp patched a zero-click flaw exploited to plant Paragon&#8217;s Graphite spyware on journalists&#8217; and activists&#8217; phones. Here&#8217;s what happened.<\/p>\n","protected":false},"author":1,"featured_media":1485,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[],"tags":[],"class_list":["post-1921","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/1921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/comments?post=1921"}],"version-history":[{"count":1,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/1921\/revisions"}],"predecessor-version":[{"id":1932,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/1921\/revisions\/1932"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media\/1485"}],"wp:attachment":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media?parent=1921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/categories?post=1921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/tags?post=1921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}