/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Citizen Lab: NSO Group deployed at least three new “zero-click” hacks against iPhones with iOS 15 and early versions of iOS 16 in 2022; Apple fixed the exploits

SAN FRANCISCOIsraeli spyware maker NSO Group deployed at least three new “zero-click” hacks against iPhones last year …

Washington Post Joseph Menn

Context & Ripple Effects

This report extends a recurring Citizen Lab-documented pattern: NSO-linked zero-click access had already been reported against iOS 13.5.1 in a campaign targeting Al Jazeera reporters and via iMessage on iOS 14.6. The new findings show that later iOS generations did not end that cycle.

Apple's fixes close the specific paths identified here, but the recurrence of a prior NSO zero-click chain against iOS 13.5.1 and iMessage-based attacks on iOS 14.6 makes exploit discovery and patch deployment central to iPhone security.

First-order effects

  • Apple's patches remove the reported exploit paths for users who update, while NSO loses at least three operational zero-click techniques against the affected iOS versions.
  • Potential targets using iOS 15 or early iOS 16 gain protection from these known flaws, but must update to receive it.

Second-order effects

  • The disclosures force commercial spyware vendors to replace burned exploit chains, increasing the value of finding new flaws that can compromise current iPhone software without user interaction.
  • Apple faces continued pressure to shorten the interval between exploit discovery and broad patch adoption, especially for attack paths associated with messaging or other remotely reachable services.

Third-order effects

  • If repeated zero-click disclosures persist across iOS releases, mobile security will increasingly be defined by an ongoing contest between well-resourced exploit suppliers and platform patching systems rather than by one-time hardening wins.
  • The pattern strengthens scrutiny of commercial spyware markets and of the product-design choices that determine how broadly security protections are delivered across jurisdictions.

The trend: This is another data point in the continuing zero-click spyware–mobile-platform patch cycle, where disclosed exploit chains are rapidly neutralized but repeatedly replaced.

Discussion

  • @runasand Runa Sandvik on x
    New report from @citizenlab details additional exploits used by NSO's Pegasus. For me, it also highlights just how beneficial Apple's Lockdown Mode has been for some of the victims. https://citizenlab.ca/... https://twitter.com/...
  • @lorenzofb @lorenzofb on x
    NEW: Apple's “extreme” privacy and security mode blocked a hacking attempt made with NSO's zero-day exploits, according to Citizen Lab. First documented case where Lockdown Mode not only blocked the attempt, but also notified the target. https://techcrunch.com/...
  • @elvanderb Eloi Benoist-Vanderbeken on x
    I can't say that I'm not impressed by NSO engineers... too bad they chose to fight for the bad guys... I'm also impressed by @citizenlab investigations! Great job! (context: https://twitter.com/...)
  • @citizenlab @citizenlab on x
    🚨NEW REPORT: NSO Group's #Pegasus #Spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains. The report finds NSO group clients deployed exploits against civil society members including two human right defenders in #Mexico https://citizenlab.ca/...
  • @rondeibert @rondeibert on x
    NEW @citizenlab report: TRIPLE THREATS Details 2022 Trio of Pegasus Zero-Click Exploit Chains + More Mexican 🇲🇽 Victims 👇 https://citizenlab.ca/... https://twitter.com/...
  • @techcrunch @techcrunch on x
    New: Researchers say Apple's Lockdown Mode blocked an attempted compromise by NSO's Pegasus spyware. Citizen Lab recently found three zero-day exploits in iOS 15 and iOS 16 that were used to target human rights defenders. https://techcrunch.com/...
  • @nasoskook Thanasis Koukakis on x
    Triple Threat: NSO Group's Pegasus Spyware Returns in 2022 with a Trio of iOS 15 and iOS 16 Zero-Click Exploit Chains - The Citizen Lab https://citizenlab.ca/...