The idea, without a recipe
Modern phones automatically parse incoming messages, images, link previews, and call-setup signals before a person touches anything. A zero-click chain abuses that parsing so the target never has to tap a link or open an attachment. The phone compromises itself.
Contrast this with one-click exploits, which require the target to interact — typically tapping a link. And contrast it with network injection, where traffic is redirected en route, sometimes with carrier cooperation, to deliver an exploit or implant.
Zero-click is the hardest to detect because it leaves almost no user-visible trace. Forensic labs often find it only by parsing a backup or examining device logs for indicators of compromise — and even then, implants can self-delete and logs rotate.
Why encryption does not help here
End-to-end-encrypted apps like Signal, WhatsApp, and iMessage protect data in transit. But a device-level implant reads the content after it is decrypted on the phone — the same moment the user sees it. This is why E2EE alone does not stop a resident implant, and why "I use Signal" is not, by itself, a defense against Pegasus.
Publicly named chains
The chains below are described at a high level only: what app or parser was hit, when it was active, and the patch. Each named chain was patched. New chains have historically followed patches, so an updated phone is necessary but not sufficient assurance.
WhatsApp calling (CVE-2019-3568)
Patched May 2019Android / iOS · 2019About 1,400 users targeted in April–May 2019. Patched May 2019. Internal NSO names for WhatsApp Android vectors in case documents: Heaven (first broad Android zero-click, Pegasus 2.50), Eden, and Erised (Samsung-focused); umbrella term Hummingbird.
Diablo
Patched iOS 11.x updatesiOS 11.x · 2018Described in 2018 NSO product materials filed in the WhatsApp case.
Dragonfly
Patched iOS 12.4.1iOS 12.x · 2019Active in 2019. Mitigated in iOS 12.4.1.
KISMET
Patched iOS 13.x updatesiOS 13 · 2020Used at least July–August 2020. Disclosed by Citizen Lab, December 2020. Did not work if the device was rebooted and had not since been unlocked.
FORCEDENTRY / Megalodon (CVE-2021-30860)
Patched iOS 14.8iOS 14 · 2021Malicious iMessage, in use by at least February 2021, disclosed 13 September 2021, patched in iOS 14.8. Google Project Zero called the JBIG2 logic 'a unusually sophisticated virtual CPU built inside a compression parser.' Companion WebKit issue CVE-2021-30858.
LATENTIMAGE
Patched iOS updatesiOS · 2022From January 2022. Part of Citizen Lab's 'Triple Threat' (April 2023).
FINDMYPWN
Patched iOS updatesiOS · 2022From June 2022. Part of the 'Triple Threat' reporting.
PWNYOURHOME
Patched iOS 16.3.1iOS · 2022From October 2022. Apple mitigations included iOS 16.3.1 HomeKit changes. Assessed vector for the 2022 Kouloglou infection.
BLASTPASS (CVE-2023-41064, CVE-2023-41061)
Patched iOS 16.6.1iOS 16 · 20237 September 2023, Citizen Lab. Malicious PassKit image via iMessage. Patched same day in iOS 16.6.1. Used to deliver Pegasus to at least one civil-society iPhone; also affected Lockdown Mode targets in that case.
Serbia iMessage zero-click
Patched iOS 18.4.1iOS 18 · 2025–2026Citizen Lab with SHARE Foundation, published 2 September 2026. High-confidence infection window December 2025–January 2026 on a student-movement iPhone. Patched as of iOS 18.4.1. At least 14 Apple threat notifications in Serbia's protest movement, civil society, and an opposition MP.
What this page does not do
It does not provide exploit code, byte patterns, payloads, reproduction steps, or any instruction for building, buying, deploying, or hiding spyware. It describes only what has been publicly documented by forensic labs, courts, and security vendors.

