Citizen Lab: in 2022, NSO Group deployed at least three new zero-click hacks against iPhones with iOS 15 and early versions of iOS 16; Apple fixed the flaws
This was an experiment by #apple around #iOS, without guarantees it would do anything. — But it did. — Concerned about security? … John Scott-Railton / @jsrailton@mastodon.social : 3/ Some details about the #zeroclick #zeroday exploits in #Pegasus #spyware that we found evidence of. — *THREE* #zeroclick #0day chains used by NSO's #Pegasus #spyware in 2022. … Tweets: @lorenzofb : NEW: Apple's “extreme” privacy and security mode blocked a hacking attempt made with NSO's zero-day exploits, according to Citizen Lab. First documented case where Lockdown Mode not only blocked the attempt, but also notified the target. https://techcrunch.com/... John Scott-Railton / @jsrailton : NEW INVESTIGATION: recent Mexican #Pegasus spyware abuses led us to evidence of a trio of zero-click exploits used by #NSO. Targets? HomeKit & FindMy. Remarkably, #Apple's #iOS #LockdownMode blocked one of them. Quick THREAD 1/ https://citizenlab.ca/... https://twitter.com/... Runa Sandvik / @runasand : New report from @citizenlab details additional exploits used by NSO's Pegasus. For me, it also highlights just how beneficial Apple's Lockdown Mode has been for some of the victims. https://citizenlab.ca/... https://twitter.com/... Joseph Menn / @josephmenn : NSO keeps finding new ways to attack iPhones with zero user clicks. But they are getting caught faster. https://www.washingtonpost.com/ ... Eloi Benoist-Vanderbeken / @elvanderb : I can't say that I'm not impressed by NSO engineers... too bad they chose to fight for the bad guys... I'm also impressed by @citizenlab investigations! Great job! (context: https://twitter.com/...) @citizenlab : 🚨NEW REPORT: NSO Group's #Pegasus #Spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains. The report finds NSO group clients deployed exploits against civil society members including two human right defenders in #Mexico https://citizenlab.ca/... @rondeibert : NEW @citizenlab report: TRIPLE THREATS Details 2022 Trio of Pegasus Zero-Click Exploit Chains + More Mexican 🇲🇽 Victims 👇 https://citizenlab.ca/... https://twitter.com/... @techcrunch : New: Researchers say Apple's Lockdown Mode blocked an attempted compromise by NSO's Pegasus spyware. Citizen Lab recently found three zero-day exploits in iOS 15 and iOS 16 that were used to target human rights defenders. https://techcrunch.com/... Thanasis Koukakis / @nasoskook : Triple Threat: NSO Group's Pegasus Spyware Returns in 2022 with a Trio of iOS 15 and iOS 16 Zero-Click Exploit Chains - The Citizen Lab https://citizenlab.ca/...
Context & Ripple Effects
This sits in a recurring Citizen Lab record of commercial spyware reaching iPhones through interaction-free attack chains: a 2020 Pegasus campaign targeting Al Jazeera reporters and later reporting on QuaDream’s iPhone targeting show the issue is not confined to one vendor.
Apple had already patched flaws that bypassed its Blastdoor protections in the iOS 14.8 security update. This case matters because it documents both continued exploit development against later iOS versions and a defensive feature stopping an attempted compromise.
First-order effects
- Apple’s patches close the identified iOS 15 and early-iOS-16 attack paths for users who update, while Lockdown Mode gains a documented success against one Pegasus attempt.
- NSO Group’s clients lose at least three observed zero-click chains, including ones Citizen Lab tied to targeting civil-society figures in Mexico.
Second-order effects
- High-risk iPhone users and the organizations supporting them have a stronger reason to enable Lockdown Mode and keep devices updated, rather than relying solely on ordinary platform protections.
- The documented failure of one chain raises the cost for mercenary-spyware operators: they must seek new vulnerabilities or techniques that can evade Apple’s hardened modes.
Third-order effects
- The pattern suggests mobile security is becoming a continuing contest between platform-level hardening and a commercial market for high-value exploit chains, rather than a problem solved by individual patches.
- If independent researchers continue to attribute attacks and defenses this precisely, pressure will grow for clearer accountability around spyware vendors and the clients that deploy their tools.
The trend: Zero-click spyware is pushing mobile platforms toward opt-in high-security modes and faster patching as standard defenses face targeted commercial exploit development.