/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Investigation details ForcedEntry, an iMessage “zero-click” attack used by NSO Group that circumvents iOS 14's BlastDoor, likely used by the Bahraini government

Summary & Key Findings  — We identified nine Bahraini activists whose iPhones were successfully hacked …

The Citizen Lab

Context & Ripple Effects

Earlier coverage documented an NSO zero-click iMessage chain used against roughly 36 Al Jazeera reporters on iOS 13.5.1. ForcedEntry shows that the threat persisted after Apple introduced BlastDoor, with a different set of targets in Bahrain.

The finding also sits in a broader pattern of mobile-spyware exploit reuse: QuaDream was later reported to have used ForcedEntry, while subsequent research identified new NSO zero-click attacks against iOS 15 and early iOS 16.

First-order effects

  • Nine Bahraini activists had their iPhones compromised, giving the suspected operator access through an attack that required no interaction from the targets.
  • Apple's BlastDoor protection in iOS 14 was shown to be insufficient against ForcedEntry, leaving a specific iMessage attack path available to NSO Group.

Second-order effects

  • Apple gains a concrete exploit chain to remediate; later coverage of fixes for newer NSO zero-click attacks indicates an ongoing patch cycle rather than a one-time BlastDoor solution.
  • Because ForcedEntry was also used by QuaDream, a mitigation aimed at the exploit affects more than NSO Group's customer base and raises the value of independently finding shared spyware techniques.

Third-order effects

  • Repeated zero-click compromises across successive iOS versions point to a durable contest between Apple’s platform defenses and commercial spyware vendors’ exploit development, with researchers’ detections serving as a key corrective mechanism.
  • If exploit reuse across vendors continues, mobile-security exposure will be shaped less by a single supplier than by the circulation of high-value attack chains among surveillance providers and their government clients.

The trend: Commercial spyware vendors are sustaining zero-click iPhone access through evolving and sometimes shared exploit chains despite successive iOS security defenses.

Discussion

  • @0xmachos Mikey on x
    Details an exploit they call FORCEDENTRY. Works against iOS 14.x and bypasses the MessagesBlastDoorService which Apple added in iOS 14 to make iMessage exploitation more difficult. FORCEDENTRY similar to Megalodon exploitation activity observed by Amnesty Tech earlier this year h…
  • @runasand Runa Sandvik on x
    When asked about the latest iMessage exploit, Apple told @zackwhittaker that “it has strengthened its defenses in iOS 15, which is slated for release in the next month or so.” In other words: there's no immediate patch for this. https://techcrunch.com/...
  • @zackwhittaker Zack Whittaker on x
    New: Citizen Lab has discovered a new NSO “zero-click” attack that circumvents Apple's ‘BlastDoor’ security defenses in iOS 14. At least one activist's iPhone was hacked with Pegasus spyware. Apple said it's aware, but no word yet on a security fix. https://techcrunch.com/...
  • @zackwhittaker Zack Whittaker on x
    Apple says it “unequivocally condemns” cyberattacks against journalists and human rights defenders, while also telling those same victims — who've just had their iPhones hacked — to basically just wait patiently for a month or two until iOS 15 comes out. https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    Apple said BlastDoor was “not the end of its efforts to secure iMessage” and pointed to iOS 15, which is slated for released in the next month or so. But Apple wouldn't say if it had fixed the flaw in current versions of iOS 14, or say when — if at all. https://techcrunch.com/...
  • @citizenlab @citizenlab on x
    Two of the activists now reside in London, and at least one was in London when they were hacked. We have only ever seen the Bahrain government spying in Bahrain and Qatar. Thus, the activist in London may have been hacked by a Pegasus operator associated w a different government.
  • @zackwhittaker Zack Whittaker on x
    The new exploit, called ForcedEntry, targeted a Bahraini human rights activist living in Bahrain, and likely hacked by the Bahraini government using an iOS 14 exploit to deploy Pegasus, said Citizen Lab. Eight other Bahrainis were also targeted, including @moosaakrawi in London. …
  • @citizenlab @citizenlab on x
    The hacked activists included three members of Waad (a secular Bahraini political society), three members of the Bahrain Center for Human Rights, two exiled Bahraini dissidents, and one member of Al Wefaq (a Shiite Bahraini political society).
  • @citizenlab @citizenlab on x
    At least four of the activists were hacked by LULU, a Pegasus operator that we attribute with high confidence to the government of Bahrain, a well-known abuser of spyware. One of the activists was hacked hours after they revealed that their phone was hacked with Pegasus in 2019.
  • @citizenlab @citizenlab on x
    We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group's Pegasus spyware from June 2020 - February 2021. Some of the activists were hacked using two zero-click iMessage exploits: the 2020 KISMET exploit and a 2021 exploit we call FORCEDENTRY.
  • @citizenlab @citizenlab on x
    NEW REPORT From Pearl to Pegasus: Bahraini Government Hacks Activists with NSO Group Zero-Click iPhone Exploits https://citizenlab.ca/...
  • @zackwhittaker Zack Whittaker on x
    The eight other Bahrainis were targeted with a different, older kind of NSO zero-click that predates ForcedEntry, called Kismet, which doesn't work on iOS 14 (because of BlastDoor). Five of the activists were on the #PegasusProject list of phone numbers. https://techcrunch.com/..…
  • @citizenlab @citizenlab on x
    We shared a list of the targeted phone numbers we identified with Forbidden Stories. They confirmed that numbers associated with five of the hacked devices were contained on the Pegasus Project's list of potential targets of NSO Group's customers.