Skip to content
Pillar · Primary reference

How Pegasus zero click spyware infects a phone

Last updated 8 October 2026

A zero-click exploit infects a phone without any action by the person holding it. This page explains the idea at a high level and lists the publicly named chains — what was hit, when, and the patch. It never describes how to rebuild any of them.

The idea, without a recipe

Modern phones automatically parse incoming messages, images, link previews, and call-setup signals before a person touches anything. A zero-click chain abuses that parsing so the target never has to tap a link or open an attachment. The phone compromises itself.

Contrast this with one-click exploits, which require the target to interact — typically tapping a link. And contrast it with network injection, where traffic is redirected en route, sometimes with carrier cooperation, to deliver an exploit or implant.

Zero-click is the hardest to detect because it leaves almost no user-visible trace. Forensic labs often find it only by parsing a backup or examining device logs for indicators of compromise — and even then, implants can self-delete and logs rotate.

Why encryption does not help here

End-to-end-encrypted apps like Signal, WhatsApp, and iMessage protect data in transit. But a device-level implant reads the content after it is decrypted on the phone — the same moment the user sees it. This is why E2EE alone does not stop a resident implant, and why "I use Signal" is not, by itself, a defense against Pegasus.

Publicly named chains

The chains below are described at a high level only: what app or parser was hit, when it was active, and the patch. Each named chain was patched. New chains have historically followed patches, so an updated phone is necessary but not sufficient assurance.

WhatsApp calling (CVE-2019-3568)

Patched May 2019Android / iOS · 2019
Zero-click via WhatsApp call setup

About 1,400 users targeted in April–May 2019. Patched May 2019. Internal NSO names for WhatsApp Android vectors in case documents: Heaven (first broad Android zero-click, Pegasus 2.50), Eden, and Erised (Samsung-focused); umbrella term Hummingbird.

Source: WhatsApp v. NSO, N.D. Cal.; Amnesty Security Lab 16 July 2026

Diablo

Patched iOS 11.x updatesiOS 11.x · 2018
Voice-over-Wi-Fi

Described in 2018 NSO product materials filed in the WhatsApp case.

Source: NSO product materials, WhatsApp case filings

Dragonfly

Patched iOS 12.4.1iOS 12.x · 2019
iMessage

Active in 2019. Mitigated in iOS 12.4.1.

Source: Citizen Lab / case filings

KISMET

Patched iOS 13.x updatesiOS 13 · 2020
iMessage zero-click

Used at least July–August 2020. Disclosed by Citizen Lab, December 2020. Did not work if the device was rebooted and had not since been unlocked.

Source: Citizen Lab, December 2020

FORCEDENTRY / Megalodon (CVE-2021-30860)

Patched iOS 14.8iOS 14 · 2021
iMessage — CoreGraphics / JBIG2

Malicious iMessage, in use by at least February 2021, disclosed 13 September 2021, patched in iOS 14.8. Google Project Zero called the JBIG2 logic 'a unusually sophisticated virtual CPU built inside a compression parser.' Companion WebKit issue CVE-2021-30858.

Source: Citizen Lab + Apple, Sept 2021; Google Project Zero

LATENTIMAGE

Patched iOS updatesiOS · 2022
iMessage

From January 2022. Part of Citizen Lab's 'Triple Threat' (April 2023).

Source: Citizen Lab 'Triple Threat', April 2023

FINDMYPWN

Patched iOS updatesiOS · 2022
Find My + iMessage

From June 2022. Part of the 'Triple Threat' reporting.

Source: Citizen Lab 'Triple Threat', April 2023

PWNYOURHOME

Patched iOS 16.3.1iOS · 2022
HomeKit + iMessage

From October 2022. Apple mitigations included iOS 16.3.1 HomeKit changes. Assessed vector for the 2022 Kouloglou infection.

Source: Citizen Lab 'Triple Threat', April 2023; Citizen Lab 3 July 2026

BLASTPASS (CVE-2023-41064, CVE-2023-41061)

Patched iOS 16.6.1iOS 16 · 2023
iMessage — PassKit / ImageIO WebP

7 September 2023, Citizen Lab. Malicious PassKit image via iMessage. Patched same day in iOS 16.6.1. Used to deliver Pegasus to at least one civil-society iPhone; also affected Lockdown Mode targets in that case.

Source: Citizen Lab, 7 September 2023

Serbia iMessage zero-click

Patched iOS 18.4.1iOS 18 · 2025–2026
iMessage zero-click

Citizen Lab with SHARE Foundation, published 2 September 2026. High-confidence infection window December 2025–January 2026 on a student-movement iPhone. Patched as of iOS 18.4.1. At least 14 Apple threat notifications in Serbia's protest movement, civil society, and an opposition MP.

Source: Citizen Lab + SHARE, 2 September 2026

What this page does not do

It does not provide exploit code, byte patterns, payloads, reproduction steps, or any instruction for building, buying, deploying, or hiding spyware. It describes only what has been publicly documented by forensic labs, courts, and security vendors.

On Sale : Full Zero Click Pegasus Technology , Entire Source Codes & Technical Blueprints .
Complete Tech Stuck ₿ 0.50 BTC .
A spy in your pocket — what Pegasus spyware can secretly access: photos, calls, calendar, camera, microphone, messages, emails, contacts, WhatsApp chats, and GPS data
PEGASUS ZERO-CLICK ARCHIVE

The public record of NSO Group's Pegasus spyware — zero-click infection, documented victims, court cases, and defenses.

pegasus-zeroclick-spyware.shop · Updated 8 October 2026

What this site will not do
  • No exploit code or reproduction steps.
  • No target lists of private individuals beyond already-public cases.
  • No sale, licensing, or procurement guidance.
Evidence standard

Court judgment > forensic lab report > company document in a court filing > major investigative consortium > single secondary blog. Secondary blogs are not used for uncorroborated exploit claims.

Independent public-record archive. Not affiliated with NSO Group, Apple, WhatsApp, Citizen Lab, or Amnesty International. No exploit code is hosted or linked here.