Investigation details ForcedEntry, an iMessage “zero-click” attack used by NSO Group that circumvents iOS 14's BlastDoor, likely used by the Bahraini government
Targets selected by the Bahraini government were exposed to a no-interaction iPhone compromise route, according to the investigation’s attribution.
Apple’s BlastDoor sandbox did not contain ForcedEntry, leaving NSO Group with an iMessage path around a central iOS 14 mitigation.
Second-order effects
The documented bypass gives Apple and independent security researchers a concrete exploit chain to analyze, while increasing pressure on NSO’s iMessage-based tooling.
Repeated findings spanning iOS 14-era protections indicate that platform hardening alone does not end the targeted-spyware cycle; it shifts the contest toward newly discovered exploit chains and faster remediation.
If governments continue procuring tools capable of silent phone compromise, scrutiny will increasingly center on the vendors supplying those capabilities and the governments deploying them.
The trend: Targeted surveillance vendors are continuing to pursue zero-click mobile exploits even as Apple adds message-processing defenses such as BlastDoor.
Your @apple phones are not safe. Nation states have back doors. Given the rapid pace of tech/government intrusion/violation of any and all privacy rights, it is time to start looking for other alternatives. https://techcrunch.com/...
Israel's NSO Group continues its sordid partnership with Bahrain in a campaign to spy on human rights activists there and in Europe. https://citizenlab.ca/...
Sometimes I think it gets lost that basically we have a UK private equity firm & an Israeli surveillance company investing millions into breaking American software, so that they can make a profit from spying. https://twitter.com/...
When asked about the latest iMessage exploit, Apple told @zackwhittaker that “it has strengthened its defenses in iOS 15, which is slated for release in the next month or so.” In other words: there's no immediate patch for this. https://techcrunch.com/...
Citizen Lab researchers found Bahrain used NSO Group spyware to target nine human rights activists. Of them, seven live in the country, two are in exile in the UK. Five of them were on 50,000 numbers list obtained by Forbidden Stories and Amnesty. https://citizenlab.ca/...
Getting to it “next month” is a very bad answer for an actively exploited issue. In my guest spot on last week's @SCWpod I mostly talked about architectural security and safe coding between browsers. We didn't get into vuln response, but it's always been a weak point for Apple. h…
Researchers at Citizen Lab discovered a new NSO “zero-click” attack that circumvents a new software security feature, BlastDoor. Citizen Lab told TechCrunch that the researchers made Apple aware of the efforts to target and exploit up-to-date iPhones. https://techcrunch.com/...
Suggestions for Pres: “Satya, attacks against Azure are a BFD. When are you going to provide all security features below the E5 license?” “Tim, I see that NSO group pwned you up again. iOS security is currently malarkey. What are you doing about that?” https://www.theverge.com/..…
New: Citizen Lab has discovered a new NSO “zero-click” attack that circumvents Apple's ‘BlastDoor’ security defenses in iOS 14. At least one activist's iPhone was hacked with Pegasus spyware. Apple said it's aware, but no word yet on a security fix. https://techcrunch.com/...
Details an exploit they call FORCEDENTRY. Works against iOS 14.x and bypasses the MessagesBlastDoorService which Apple added in iOS 14 to make iMessage exploitation more difficult. FORCEDENTRY similar to Megalodon exploitation activity observed by Amnesty Tech earlier this year h…
Apple says it “unequivocally condemns” cyberattacks against journalists and human rights defenders, while also telling those same victims — who've just had their iPhones hacked — to basically just wait patiently for a month or two until iOS 15 comes out. https://twitter.com/...
Apple said BlastDoor was “not the end of its efforts to secure iMessage” and pointed to iOS 15, which is slated for released in the next month or so. But Apple wouldn't say if it had fixed the flaw in current versions of iOS 14, or say when — if at all. https://techcrunch.com/...
The eight other Bahrainis were targeted with a different, older kind of NSO zero-click that predates ForcedEntry, called Kismet, which doesn't work on iOS 14 (because of BlastDoor). Five of the activists were on the #PegasusProject list of phone numbers. https://techcrunch.com/..…
Two of the activists now reside in London, and at least one was in London when they were hacked. We have only ever seen the Bahrain government spying in Bahrain and Qatar. Thus, the activist in London may have been hacked by a Pegasus operator associated w a different government.
The hacked activists included three members of Waad (a secular Bahraini political society), three members of the Bahrain Center for Human Rights, two exiled Bahraini dissidents, and one member of Al Wefaq (a Shiite Bahraini political society).
At least four of the activists were hacked by LULU, a Pegasus operator that we attribute with high confidence to the government of Bahrain, a well-known abuser of spyware. One of the activists was hacked hours after they revealed that their phone was hacked with Pegasus in 2019.
We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group's Pegasus spyware from June 2020 - February 2021. Some of the activists were hacked using two zero-click iMessage exploits: the 2020 KISMET exploit and a 2021 exploit we call FORCEDENTRY.
We shared a list of the targeted phone numbers we identified with Forbidden Stories. They confirmed that numbers associated with five of the hacked devices were contained on the Pegasus Project's list of potential targets of NSO Group's customers.
The new exploit, called ForcedEntry, targeted a Bahraini human rights activist living in Bahrain, and likely hacked by the Bahraini government using an iOS 14 exploit to deploy Pegasus, said Citizen Lab. Eight other Bahrainis were also targeted, including @moosaakrawi in London. …