One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware
## Cybersecurity: An Overview of Zero-Click Exploits in 2025
Cybersecurity: An Overview of Zero-Click Exploits in 2025
In 2025, zero-click exploitation techniques have undergone significant developments, presenting new challenges to digital security frameworks. Unlike traditional cyberattacks that require user interaction, zero-click exploits infiltrate devices without any user involvement.
This year has seen the emergence of at least 14 notable zero-click vulnerabilities affecting billions of devices globally. This development has highlighted the growing risk of automated processes becoming attack vectors, expanding the attack surface beyond human error.
Zero-click attacks have evolved, exploiting the convenience features designed for seamless user experiences. Google's Threat Intelligence Group reported 75 zero-day vulnerabilities being actively exploited in 2024, with this trend continuing into 2025, primarily targeting enterprise infrastructure.
Increase in Vulnerabilities and Exploitation
In the first half of 2025, over 21,500 Common Vulnerabilities and Exposures (CVEs) were disclosed, marking an 18% increase compared to the previous year. The average time to exploit these vulnerabilities has decreased to just five days in 2024, from 32 days in prior years, challenging the efficacy of traditional patch cycles.
These developments reflect the advanced automation employed by nation-state actors, commercial surveillance vendors, and ransomware groups, who have streamlined the process of exploiting vulnerabilities. Zero-click vulnerabilities have become prevalent across the threat spectrum.
Apple's ecosystem experienced persistent attacks throughout 2025. A critical vulnerability, CVE-2025-43300 , disclosed in August, affected iOS, iPadOS, and macOS. It enabled zero-click remote code execution via malicious DNG images, posing significant risks when combined with other vulnerabilities.
In 2025, zero-click exploitation techniques have undergone significant developments, presenting new challenges to digital security frameworks.
WhatsApp confirmed fewer than 200 targeted users in sophisticated spyware campaigns, affecting human rights defenders and media professionals. Paragon Solutions' Graphite spyware exploited CVE-2025-43200 , further demonstrating the vulnerability of mobile platforms.
Enterprise infrastructure has also been a target, with CVE-2025-21298 allowing zero-click remote code execution through malicious RTF documents in Microsoft Outlook. Similarly, a vulnerability in Microsoft 365 Copilot, EchoLeak , posed a risk to organizational data.
OpenAI's ChatGPT agent was affected by ShadowLeak , which enabled silent Gmail data theft, illustrating the vulnerabilities in AI systems.
Apple's AirPlay protocol revealed 17 vulnerabilities, named AirBorne , which allowed zero-click remote code execution on macOS devices on the same network. These vulnerabilities were particularly concerning due to their wormable nature, enabling them to spread autonomously.
The React2Shell vulnerability (CVE-2025-55182) affected React Server Components and Next.js, allowing remote code execution through a malicious HTTP request.
The events of 2025 underline the necessity for rapid patching and defense-in-depth strategies, as zero-click exploits have become prominent attack vectors. Organizations are urged to adopt risk-based patching, prioritize actively exploited vulnerabilities, and implement zero-trust architectures to mitigate such threats.
As zero-click exploits transition into mainstream attack strategies, rethinking security measures and continuously verifying trust are essential to counter this evolving threat landscape.
Based on reporting by Cyber Security News.
