Exploit Timeline
A chronological record of publicly named Pegasus exploit chains, court actions, and major disclosures — filter by type. Each entry is sourced; each exploit entry is patched.
Ahmed Mansoor — first public forensic case
ForensicCitizen Lab and Lookout analyze Pegasus delivered via one-click SMS links in the UAE.
Diablo
Patched iOS 11.x updatesDescribed in 2018 NSO product materials filed in the WhatsApp case.
WhatsApp calling (CVE-2019-3568)
Patched May 2019About 1,400 users targeted in April–May 2019. Patched May 2019. Internal NSO names for WhatsApp Android vectors in case documents: Heaven (first broad Android zero-click, Pegasus 2.50), Eden, and Erised (Samsung-focused); umbrella term Hummingbird.
Dragonfly
Patched iOS 12.4.1Active in 2019. Mitigated in iOS 12.4.1.
WhatsApp v. NSO
CourtSummary judgment on liability 20 December 2024 (CFAA, California computer-access law, breach of contract). Jury 6 May 2025: $444,719 compensatory + $167,254,000 punitive. Judge Phyllis Hamilton, 17 October 2025: punitive damages remitted to $4,002,471; permanent injunction barring NSO from targeting WhatsApp users. Plaintiffs accepted remittitur 31 October 2025. Final judgment $4,447,190. Injunction entered 12 November 2025.
KISMET
Patched iOS 13.x updatesUsed at least July–August 2020. Disclosed by Citizen Lab, December 2020. Did not work if the device was rebooted and had not since been unlocked.
FORCEDENTRY / Megalodon (CVE-2021-30860)
Patched iOS 14.8Malicious iMessage, in use by at least February 2021, disclosed 13 September 2021, patched in iOS 14.8. Google Project Zero called the JBIG2 logic 'a unusually sophisticated virtual CPU built inside a compression parser.' Companion WebKit issue CVE-2021-30858.
Apple v. NSO
CourtLater dropped (Apple withdrew; widely reported 2023–2024), reportedly to avoid disclosing security methods.
US Commerce Entity List
CourtNSO Group added for supplying spyware used to target officials, journalists, activists, and embassy workers.
The Pegasus Project
LeakForbidden Stories + Amnesty + 17 outlets publish a leaked list of ~50,000 selected numbers.
NSO added to US Entity List
SanctionUS Commerce Department adds NSO Group for supplying spyware used to target officials, journalists, activists, and embassy workers.
LATENTIMAGE
Patched iOS updatesFrom January 2022. Part of Citizen Lab's 'Triple Threat' (April 2023).
FINDMYPWN
Patched iOS updatesFrom June 2022. Part of the 'Triple Threat' reporting.
PWNYOURHOME
Patched iOS 16.3.1From October 2022. Apple mitigations included iOS 16.3.1 HomeKit changes. Assessed vector for the 2022 Kouloglou infection.
BLASTPASS (CVE-2023-41064, CVE-2023-41061)
Patched iOS 16.6.17 September 2023, Citizen Lab. Malicious PassKit image via iMessage. Patched same day in iOS 16.6.1. Used to deliver Pegasus to at least one civil-society iPhone; also affected Lockdown Mode targets in that case.
Serbia iMessage zero-click
Patched iOS 18.4.1Citizen Lab with SHARE Foundation, published 2 September 2026. High-confidence infection window December 2025–January 2026 on a student-movement iPhone. Patched as of iOS 18.4.1. At least 14 Apple threat notifications in Serbia's protest movement, civil society, and an opposition MP.

