Citizen Lab: NSO Group deployed at least three new “zero-click” hacks against iPhones with iOS 15 and early versions of iOS 16 in 2022; Apple fixed the exploits
SAN FRANCISCO — Israeli spyware maker NSO Group deployed at least three new “zero-click” hacks against iPhones last year …
Context & Ripple Effects
This report extends a recurring Citizen Lab-documented pattern: NSO-linked zero-click access had already been reported against iOS 13.5.1 in a campaign targeting Al Jazeera reporters and via iMessage on iOS 14.6. The new findings show that later iOS generations did not end that cycle.
Apple's fixes close the specific paths identified here, but the recurrence of a prior NSO zero-click chain against iOS 13.5.1 and iMessage-based attacks on iOS 14.6 makes exploit discovery and patch deployment central to iPhone security.
First-order effects
- Apple's patches remove the reported exploit paths for users who update, while NSO loses at least three operational zero-click techniques against the affected iOS versions.
- Potential targets using iOS 15 or early iOS 16 gain protection from these known flaws, but must update to receive it.
Second-order effects
- The disclosures force commercial spyware vendors to replace burned exploit chains, increasing the value of finding new flaws that can compromise current iPhone software without user interaction.
- Apple faces continued pressure to shorten the interval between exploit discovery and broad patch adoption, especially for attack paths associated with messaging or other remotely reachable services.
Third-order effects
- If repeated zero-click disclosures persist across iOS releases, mobile security will increasingly be defined by an ongoing contest between well-resourced exploit suppliers and platform patching systems rather than by one-time hardening wins.
- The pattern strengthens scrutiny of commercial spyware markets and of the product-design choices that determine how broadly security protections are delivered across jurisdictions.
The trend: This is another data point in the continuing zero-click spyware–mobile-platform patch cycle, where disclosed exploit chains are rapidly neutralized but repeatedly replaced.