Skip to content
Chronology

Exploit Timeline

Last updated 8 October 2026

A chronological record of publicly named Pegasus exploit chains, court actions, and major disclosures — filter by type. Each entry is sourced; each exploit entry is patched.

August 2016

Ahmed Mansoor — first public forensic case

Forensic

Citizen Lab and Lookout analyze Pegasus delivered via one-click SMS links in the UAE.

Source: Citizen Lab + Lookout
2018

Diablo

Patched iOS 11.x updates

Described in 2018 NSO product materials filed in the WhatsApp case.

Source: NSO product materials, WhatsApp case filings
2019

WhatsApp calling (CVE-2019-3568)

Patched May 2019

About 1,400 users targeted in April–May 2019. Patched May 2019. Internal NSO names for WhatsApp Android vectors in case documents: Heaven (first broad Android zero-click, Pegasus 2.50), Eden, and Erised (Samsung-focused); umbrella term Hummingbird.

Source: WhatsApp v. NSO, N.D. Cal.; Amnesty Security Lab 16 July 2026
2019

Dragonfly

Patched iOS 12.4.1

Active in 2019. Mitigated in iOS 12.4.1.

Source: Citizen Lab / case filings
October 2019

WhatsApp v. NSO

Court

Summary judgment on liability 20 December 2024 (CFAA, California computer-access law, breach of contract). Jury 6 May 2025: $444,719 compensatory + $167,254,000 punitive. Judge Phyllis Hamilton, 17 October 2025: punitive damages remitted to $4,002,471; permanent injunction barring NSO from targeting WhatsApp users. Plaintiffs accepted remittitur 31 October 2025. Final judgment $4,447,190. Injunction entered 12 November 2025.

Source: N.D. Cal. 4:19-cv-07123
2020

KISMET

Patched iOS 13.x updates

Used at least July–August 2020. Disclosed by Citizen Lab, December 2020. Did not work if the device was rebooted and had not since been unlocked.

Source: Citizen Lab, December 2020
2021

FORCEDENTRY / Megalodon (CVE-2021-30860)

Patched iOS 14.8

Malicious iMessage, in use by at least February 2021, disclosed 13 September 2021, patched in iOS 14.8. Google Project Zero called the JBIG2 logic 'a unusually sophisticated virtual CPU built inside a compression parser.' Companion WebKit issue CVE-2021-30858.

Source: Citizen Lab + Apple, Sept 2021; Google Project Zero
November 2021

Apple v. NSO

Court

Later dropped (Apple withdrew; widely reported 2023–2024), reportedly to avoid disclosing security methods.

Source: Filed November 2021
3 November 2021

US Commerce Entity List

Court

NSO Group added for supplying spyware used to target officials, journalists, activists, and embassy workers.

Source: BIS
July 2021

The Pegasus Project

Leak

Forbidden Stories + Amnesty + 17 outlets publish a leaked list of ~50,000 selected numbers.

Source: Pegasus Project consortium
3 November 2021

NSO added to US Entity List

Sanction

US Commerce Department adds NSO Group for supplying spyware used to target officials, journalists, activists, and embassy workers.

Source: US Commerce BIS
2022

LATENTIMAGE

Patched iOS updates

From January 2022. Part of Citizen Lab's 'Triple Threat' (April 2023).

Source: Citizen Lab 'Triple Threat', April 2023
2022

FINDMYPWN

Patched iOS updates

From June 2022. Part of the 'Triple Threat' reporting.

Source: Citizen Lab 'Triple Threat', April 2023
2022

PWNYOURHOME

Patched iOS 16.3.1

From October 2022. Apple mitigations included iOS 16.3.1 HomeKit changes. Assessed vector for the 2022 Kouloglou infection.

Source: Citizen Lab 'Triple Threat', April 2023; Citizen Lab 3 July 2026
2023

BLASTPASS (CVE-2023-41064, CVE-2023-41061)

Patched iOS 16.6.1

7 September 2023, Citizen Lab. Malicious PassKit image via iMessage. Patched same day in iOS 16.6.1. Used to deliver Pegasus to at least one civil-society iPhone; also affected Lockdown Mode targets in that case.

Source: Citizen Lab, 7 September 2023
2025–2026

Serbia iMessage zero-click

Patched iOS 18.4.1

Citizen Lab with SHARE Foundation, published 2 September 2026. High-confidence infection window December 2025–January 2026 on a student-movement iPhone. Patched as of iOS 18.4.1. At least 14 Apple threat notifications in Serbia's protest movement, civil society, and an opposition MP.

Source: Citizen Lab + SHARE, 2 September 2026
On Sale : Full Zero Click Pegasus Technology , Entire Source Codes & Technical Blueprints .
Complete Tech Stuck ₿ 0.50 BTC .
A spy in your pocket — what Pegasus spyware can secretly access: photos, calls, calendar, camera, microphone, messages, emails, contacts, WhatsApp chats, and GPS data
PEGASUS ZERO-CLICK ARCHIVE

The public record of NSO Group's Pegasus spyware — zero-click infection, documented victims, court cases, and defenses.

pegasus-zeroclick-spyware.shop · Updated 8 October 2026

What this site will not do
  • No exploit code or reproduction steps.
  • No target lists of private individuals beyond already-public cases.
  • No sale, licensing, or procurement guidance.
Evidence standard

Court judgment > forensic lab report > company document in a court filing > major investigative consortium > single secondary blog. Secondary blogs are not used for uncorroborated exploit claims.

Independent public-record archive. Not affiliated with NSO Group, Apple, WhatsApp, Citizen Lab, or Amnesty International. No exploit code is hosted or linked here.