/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A deep dive into an NSO zero-click iMessage exploit, captured in the wild by Citizen Lab and one of the most sophisticated Google's Project Zero has seen

We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple's Security Engineering and Architecture …

Project Zero

Context & Ripple Effects

Citizen Lab had already tied NSO to zero-click iMessage attacks against Al Jazeera reporters and later identified FORCEDENTRY as a chain that bypassed iOS 14's BlastDoor protections. Its captured sample moves that investigation from attribution into detailed technical examination by Google Project Zero.

The report gives Apple, Citizen Lab, and Google a shared evidentiary record for understanding a real-world exploit chain rather than an abstract vulnerability claim.

First-order effects

  • Google Project Zero can dissect FORCEDENTRY from a field-captured sample, while Citizen Lab's attribution gains a technical account of how the NSO-linked iMessage chain circumvented BlastDoor.
  • Apple's security engineering teams receive a more concrete test case for iMessage defenses, centered on an exploit already documented as active against targets.

Second-order effects

  • Public analysis narrows NSO's operational secrecy around FORCEDENTRY and gives platform defenders a clearer basis for detecting or hardening against the techniques it used.
  • The disclosure raises the bar for Apple's message-processing defenses: BlastDoor's earlier bypass becomes a specific failure mode to address, not merely a general zero-click risk.

Third-order effects

  • Later reporting that NSO deployed at least three new zero-click iPhone attacks in 2022, which Apple fixed, indicates that individual patches do not end the recurring contest between exploit development and platform mitigation.
  • Citizen Lab's field capture and Project Zero's technical analysis point toward a durable security model in which independent researchers supply the evidence that turns targeted surveillance activity into actionable platform defense.

The trend: Zero-click mobile security is becoming a recurring detect-analyze-patch cycle, with independent forensic groups increasingly supplying the evidence behind platform hardening.

Discussion

  • @i41nbeer Ian Beer on x
    Today we're publishing a detailed technical writeup of FORCEDENTRY, the zero-click iMessage exploit linked by Citizen Lab to the exploitation of journalists, activists and dissidents around the world. https://googleprojectzero.blogspot.com/ ...
  • @jsrailton John Scott-Railton on x
    NEW epic analysis by Google's Project Zero of NSO et al's FORCEDENTRY exploit. Takeaway: *enormously* sophisticated, Turing completeness. Raises big questions: ✅Who first developed it? ✅How NSO got it? ✅Where else it's been? By @i41nbeer & @5aelo https://googleprojectzero.blogspo…
  • @itswillis Tim Willis on x
    Apple should be commended for making iMessage harder to hack and the improvements they made in late 2020. These improvements have forced attackers to use the next level of exploits in their arsenals, rather than relying exclusively on old tricks. https://googleprojectzero.blogspo…
  • @suka_hiroaki Andreas Proschofsky on x
    Holy f... This might be the most crazy (unfortunately in “crazy good") exploit in like... well... ever. NSO has been using simple logical operators in an old compression format to basically build a whole virtual computer on top of it. 🤯🤯🤯 https://googleprojectzero.blogspot.com/ .…
  • @igorbrigadir Igor Brigadir on x
    This is the most incredible exploit i've seen so far.. they used a fake gif to force a PDF parser to use an old black and white compression library for printers to create logic gates and built a virtual CPU to execute code on 🥴 https://twitter.com/...
  • @stevestreza @stevestreza on x
    - Fake GIF file, sure - Secretly a PDF, yeah ok - Uses an obscure image format, makes sense - Overwrites memory, should be hardened better but yep - Integer overflow, classic - Implements logical AND/OR/NOR/XNOR gates, okay what - Builds a custom virtual CPU architecture???? WHAT…
  • @matthew_d_green Matthew Green on x
    I got to this part in the exploit description and it stopped being an exploit, became something more like art. https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    4/ Key point here about the impact of Apple's continuing push to price-out less sophisticated operators. Another takeaway, as ever, is: update your iPhone! https://twitter.com/...
  • @clearing_fog ClearingTheFog on x
    Yes, who did first develop the NSO exploit and how did they get it? And where else is it being used? Excellent questions. https://twitter.com/...
  • @mikarv Michael Veale on x
    this is a pretty incredible read giving an insight into how NSO used an flakey compression tool in XPDF used by old scanners with iMessage's GIF functionality to simulate turing complete logic circuits and build a rudimentary mini computer in out-of-bounds memory. https://twitter…
  • @evacide Eva on x
    This is some very fancy work, breaking down NSO Group's iMessage exploit. https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    As John points out, Magnitsky follows you. Wouldn't matter if NSO execs sell Pegasus and pivot to “Palantir 2.0” as they've floated. https://twitter.com/...
  • @dalperovitch Dmitri Alperovitch on x
    Wow. Just wow. This NSO zero-click iMessage exploit is the most impressive attack code I've ever seen. A whole computer architecture built out of a few logic operators... in an EXPLOIT! The talent of the individuals who came up and developed this technique is beyond impressive ht…
  • @nickstenning Nick Stenning on x
    This is a mind-blowing description of an incredibly sophisticated exploit against iMessage. I can say with confidence: you will not know where this write-up is going until you get there. https://twitter.com/...
  • @jrozner Joe Rozner on x
    This is fucking ridiculous. I wonder what the meeting was like where someone shared the bug and was like, “now hear me out, I have this crazy idea about how to actually use this.” https://twitter.com/...
  • @royalhansen @royalhansen on x
    “we assess this to be one of the most technically sophisticated exploits we've ever seen, further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states.” https://googleprojectzero.blogspot.com/ ...
  • @domchell Dominic Chell on x
    Jaw dropping, matrix levels of exploitation 🤯 https://twitter.com/...
  • @thelunarixus Nathan on x
    As much as it's terrifying that NSO were the ones possessing this exploit this writeup does still show how incredibly creative exploitation can be, as much as they work for a horrible company shout-out to the researchers who found this, I'm definitely impressed. https://twitter.c…
  • @evacide Eva on x
    Seriously, if you know the person who wrote the iMessage exploit, get them a job at Project Zero or something. You will be saving so many lives. https://twitter.com/...
  • @federicomena FedericoMenaQuintero on x
    I urge all of my @gnome friends to take 30 mins to read this. An XPDF vulnerability (think: poppler) was used to hack journalists. A guint counter overflows, and unchecked array access is later used to corrupt GLists and build a virtual machine (!!!) under attacker's control. htt…
  • @benhammersley Ben Hammersley on x
    The sheer intellectual audacity of this exploit. Just...wow https://twitter.com/...
  • @itswillis Tim Willis on x
    I usually let the team's work speak for itself, but I wanted to make sure a few larger points aren't lost in this work. Firstly, the takeaway here isn't “NSO exceptionalism”. It's just that NSO was caught this time and we get a peek at how they are attacking iOS/iMessage. https:/…
  • @joshavant Josh Avant on x
    Tl;dr the NSO zero-click iMessage exploit leveraged an obscure 90s image compression codec in a FOSS decoder used by Apple to run arbitrary AND/OR/XOR/XNOR logic and bootstrap their own *microarchitecture* to achieve the exploit... Absolutely stunning. https://googleprojectzero.b…
  • @itswillis Tim Willis on x
    Finally, shoutouts to Apple and Citizen Lab, especially @radian and @jsrailton. Working together on this stuff can be complex for a number of reasons, but we made it work. Looking forward to a future post (currently being written) on the analysis of the sandbox escape. [fin]
  • @jsrailton John Scott-Railton on x
    2/ One of the most sophisticated exploits Project Zero has ever seen. Moreover, this kind of capability was previously only seen with top tier cyber powers. Should send a chill down your spine. Underlines just how dangerous NSO & peers are. https://twitter.com/...
  • @itswillis Tim Willis on x
    There are many companies that provide similar exploitation capabilities and services, and some more visible than others (e.g. the “US Entity List"). Taking action against one company (NSO), while noble and fosters a discussion, doesn't address the root of this problem.
  • @itswillis Tim Willis on x
    Controls may help, but they are difficult to get right, with a high chance of constraining security research while insufficiently controlling the problem. An echo of this NSO issue is the story of HackingTeam back in 2014. https://theintercept.com/...
  • @jsrailton John Scott-Railton on x
    3/ Recommended thread by Project Zero's @itswillis on implications of this wildly-sophisticated exploit. https://twitter.com/...
  • @josephmenn Joseph Menn on x
    Exclusive: Wyden, Schiff and 16 others in Congress call for Magnitsky Sanctions on NSO Group and other surveillance firms. https://www.reuters.com/...
  • @jsrailton John Scott-Railton on x
    BREAKING: senior US lawmakers call for NSO execs & peer companies to be sanctioned w/Global Magnitsky Act for facilitating torture & murder. Big names including: Senate Finance Chair @RonWyden House Intel Chair @RepAdamSchiff +16 other lawmakers. 1/ https://www.reuters.com/... ht…
  • @reuterslegal @reuterslegal on x
    A letter by U.S. democratic lawmakers seen by Reuters asks for sanctions on top executives at cyber firm NSO and others who are accused of enabling human rights abuses including freezing bank accounts and banning travel to the U.S. https://www.reuters.com/... https://twitter.com/…
  • @silvermanjacob Jacob Silverman on x
    NSO Group deserves everything that's coming to them, though it's an industry that extends far beyond them. https://www.reuters.com/...
  • @ronwyden Ron Wyden on x
    I'm calling on the Biden administration to sanction hacking companies that helped tyrants target activists, journalists and political rivals. These companies must be held accountable for enabling human rights abuses by selling surveillance technology to authoritarian governments.…
  • @bing_chris Chris Bing on x
    A significant development in the escalating battle between Washington and international digital surveillance vendors over the last year https://twitter.com/...
  • @talkopan Tal Kopan on x
    This is notable. Wyden is a privacy hawk, but both he and Schiff are prominent Intel Committee members who don't put their names on things like this lightly. https://twitter.com/...
  • @billbrowder Bill Browder on x
    U.S. lawmakers call for Global Magnitsky sanctions against Israel's NSO, spyware firms. Excellent initiative which should be implemented immediately. Many dead people as a result of this pernicious technology. https://www.reuters.com/...
  • @loujainhathloul @loujainhathloul on x
    Bravo! Accountability and a safe online space is all we ask for. https://twitter.com/...
  • @rosscoulthart Ross Coulthart on x
    Great to see this action from the US. Remember, NSO's grubby Pegasus spy software was used by the Saudis to spy on journalist Jamal Khashoggi and his family before and after he was dismembered by Saudi Govt killers. https://www.theguardian.com/ ... https://twitter.com/...
  • @davidakaye David Kaye on x
    a @josephmenn @joel_schectman scoop on congressional call for magnitsky sanctions ag NSO Group. #Pegasus @RonWyden: “The Biden administration has the chance to turn off the spigot of American dollars and help put them out of business for good.” https://twitter.com/...
  • @dylanotes Dylan Williams on x
    A lot going on in US-Israel relations as always, but significant, building American anger over NSO Group has potentially far-reaching implications https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    Wyden continues to lead the push to apply the Magnitsky act against NSO Group. Schiff and 16 others join him and add DarkMatter (the UAE surveillance firm featured here https://www.nytimes.com/...) and EU surveillance companies Nexa and Trovicor to the list. https://twitter.com/.…