A deep dive into an NSO zero-click iMessage exploit, captured in the wild by Citizen Lab and one of the most sophisticated Google's Project Zero has seen
We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us, and Apple's Security Engineering and Architecture …
Project Zero
Context & Ripple Effects
Citizen Lab had already tied NSO to zero-click iMessage attacks against Al Jazeera reporters and later identified FORCEDENTRY as a chain that bypassed iOS 14's BlastDoor protections. Its captured sample moves that investigation from attribution into detailed technical examination by Google Project Zero.
The report gives Apple, Citizen Lab, and Google a shared evidentiary record for understanding a real-world exploit chain rather than an abstract vulnerability claim.
First-order effects
- Google Project Zero can dissect FORCEDENTRY from a field-captured sample, while Citizen Lab's attribution gains a technical account of how the NSO-linked iMessage chain circumvented BlastDoor.
- Apple's security engineering teams receive a more concrete test case for iMessage defenses, centered on an exploit already documented as active against targets.
Second-order effects
- Public analysis narrows NSO's operational secrecy around FORCEDENTRY and gives platform defenders a clearer basis for detecting or hardening against the techniques it used.
- The disclosure raises the bar for Apple's message-processing defenses: BlastDoor's earlier bypass becomes a specific failure mode to address, not merely a general zero-click risk.
Third-order effects
- Later reporting that NSO deployed at least three new zero-click iPhone attacks in 2022, which Apple fixed, indicates that individual patches do not end the recurring contest between exploit development and platform mitigation.
- Citizen Lab's field capture and Project Zero's technical analysis point toward a durable security model in which independent researchers supply the evidence that turns targeted surveillance activity into actionable platform defense.
The trend: Zero-click mobile security is becoming a recurring detect-analyze-patch cycle, with independent forensic groups increasingly supplying the evidence behind platform hardening.
Related: Proof-carrying security report · Dual-use code intelligence · Citizen Lab · NSO · Investigation details FORCEDENTRY and its BlastDoor bypass · NSO's later zero-click iPhone attacks
Related Coverage
- View article Mercury News
- View article 9to5Mac
- View article Engadget
- View article Metacurity
- Google: This zero-click iPhone attack was incredible and terrifying ZDNet · Liam Tung
- Start Up No.1703: Chinese hackers try log4j flaw, inside an NSO iMessage attack, Google tries AR again, is biomass bad?, and more The Overspill · Charlesarthur
- Ian Beer publishes extensive write-up on FORCEDENTRY zero-click iMessage exploit used by NSO Group in Pegasus spyware iDownloadBlog.com · Anthony Bouchard
- A deep dive into an NSO zero-click iMessage exploit: remote code execution OSnews · Thom Holwerda
- NSO Group's exploits rival those of nation states, security researchers say AppleInsider · Mike Peterson
- A Deep Dive Into an NSO Group Zero-Click iMessage Exploit Pixel Envy · Nick Heer
- NSO Group used fake GIFs to hack Apple iMessage iTnews · Juha Saarinen
- Google Project Zero Goes Deep on FORCEDENTRY Exploit Used by NSO Group PCMag · Nathaniel Mott
- Google Warns That NSO Hacking Is On Par With Elite Nation-State Spies Wired · Lily Hay Newman
- Wyden, Schiff, Meeks and Maloney Lead House and Senate Democrats in Calling for Magnitsky Act Sanctions Against Companies That Enable Human Rights Abuses House Foreign Affairs Committee
- US lawmakers call for Israeli spyware firm, other groups to be sanctioned The Hill · Mychael Schnell
- US lawmakers call on Biden administration to sanction Israeli spyware firm NSO Group The Times of Israel
- Lawmakers urge Biden administration to sanction NSO Group and other cyber surveillance firms CNN · Sean Lyngaas
- Democratic lawmakers urge sanctions on Israel's NSO Group Al-Monitor
- NSO Group's latest spyware on par with nation-state abilities, researchers say CyberScoop · AJ Vicens
- US lawmakers want to put NSO Group, 3 other spyware makers out of business with fresh severe sanctions The Register · Thomas Claburn
- NSO Group's Pegasus spyware: how we got here and what now Access Now · Faraz Ansari
Discussion
-
@i41nbeer
Ian Beer
on x
Today we're publishing a detailed technical writeup of FORCEDENTRY, the zero-click iMessage exploit linked by Citizen Lab to the exploitation of journalists, activists and dissidents around the world. https://googleprojectzero.blogspot.com/ ...
-
@jsrailton
John Scott-Railton
on x
NEW epic analysis by Google's Project Zero of NSO et al's FORCEDENTRY exploit. Takeaway: *enormously* sophisticated, Turing completeness. Raises big questions: ✅Who first developed it? ✅How NSO got it? ✅Where else it's been? By @i41nbeer & @5aelo https://googleprojectzero.blogspo…
-
@itswillis
Tim Willis
on x
Apple should be commended for making iMessage harder to hack and the improvements they made in late 2020. These improvements have forced attackers to use the next level of exploits in their arsenals, rather than relying exclusively on old tricks. https://googleprojectzero.blogspo…
-
@suka_hiroaki
Andreas Proschofsky
on x
Holy f... This might be the most crazy (unfortunately in “crazy good") exploit in like... well... ever. NSO has been using simple logical operators in an old compression format to basically build a whole virtual computer on top of it. 🤯🤯🤯 https://googleprojectzero.blogspot.com/ .…
-
@igorbrigadir
Igor Brigadir
on x
This is the most incredible exploit i've seen so far.. they used a fake gif to force a PDF parser to use an old black and white compression library for printers to create logic gates and built a virtual CPU to execute code on 🥴 https://twitter.com/...
-
@stevestreza
@stevestreza
on x
- Fake GIF file, sure - Secretly a PDF, yeah ok - Uses an obscure image format, makes sense - Overwrites memory, should be hardened better but yep - Integer overflow, classic - Implements logical AND/OR/NOR/XNOR gates, okay what - Builds a custom virtual CPU architecture???? WHAT…
-
@matthew_d_green
Matthew Green
on x
I got to this part in the exploit description and it stopped being an exploit, became something more like art. https://twitter.com/...
-
@jsrailton
John Scott-Railton
on x
4/ Key point here about the impact of Apple's continuing push to price-out less sophisticated operators. Another takeaway, as ever, is: update your iPhone! https://twitter.com/...
-
@clearing_fog
ClearingTheFog
on x
Yes, who did first develop the NSO exploit and how did they get it? And where else is it being used? Excellent questions. https://twitter.com/...
-
@mikarv
Michael Veale
on x
this is a pretty incredible read giving an insight into how NSO used an flakey compression tool in XPDF used by old scanners with iMessage's GIF functionality to simulate turing complete logic circuits and build a rudimentary mini computer in out-of-bounds memory. https://twitter…
-
@evacide
Eva
on x
This is some very fancy work, breaking down NSO Group's iMessage exploit. https://twitter.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
As John points out, Magnitsky follows you. Wouldn't matter if NSO execs sell Pegasus and pivot to “Palantir 2.0” as they've floated. https://twitter.com/...
-
@dalperovitch
Dmitri Alperovitch
on x
Wow. Just wow. This NSO zero-click iMessage exploit is the most impressive attack code I've ever seen. A whole computer architecture built out of a few logic operators... in an EXPLOIT! The talent of the individuals who came up and developed this technique is beyond impressive ht…
-
@nickstenning
Nick Stenning
on x
This is a mind-blowing description of an incredibly sophisticated exploit against iMessage. I can say with confidence: you will not know where this write-up is going until you get there. https://twitter.com/...
-
@jrozner
Joe Rozner
on x
This is fucking ridiculous. I wonder what the meeting was like where someone shared the bug and was like, “now hear me out, I have this crazy idea about how to actually use this.” https://twitter.com/...
-
@royalhansen
@royalhansen
on x
“we assess this to be one of the most technically sophisticated exploits we've ever seen, further demonstrating that the capabilities NSO provides rival those previously thought to be accessible to only a handful of nation states.” https://googleprojectzero.blogspot.com/ ...
-
@domchell
Dominic Chell
on x
Jaw dropping, matrix levels of exploitation 🤯 https://twitter.com/...
-
@thelunarixus
Nathan
on x
As much as it's terrifying that NSO were the ones possessing this exploit this writeup does still show how incredibly creative exploitation can be, as much as they work for a horrible company shout-out to the researchers who found this, I'm definitely impressed. https://twitter.c…
-
@evacide
Eva
on x
Seriously, if you know the person who wrote the iMessage exploit, get them a job at Project Zero or something. You will be saving so many lives. https://twitter.com/...
-
@federicomena
FedericoMenaQuintero
on x
I urge all of my @gnome friends to take 30 mins to read this. An XPDF vulnerability (think: poppler) was used to hack journalists. A guint counter overflows, and unchecked array access is later used to corrupt GLists and build a virtual machine (!!!) under attacker's control. htt…
-
@benhammersley
Ben Hammersley
on x
The sheer intellectual audacity of this exploit. Just...wow https://twitter.com/...
-
@itswillis
Tim Willis
on x
I usually let the team's work speak for itself, but I wanted to make sure a few larger points aren't lost in this work. Firstly, the takeaway here isn't “NSO exceptionalism”. It's just that NSO was caught this time and we get a peek at how they are attacking iOS/iMessage. https:/…
-
@joshavant
Josh Avant
on x
Tl;dr the NSO zero-click iMessage exploit leveraged an obscure 90s image compression codec in a FOSS decoder used by Apple to run arbitrary AND/OR/XOR/XNOR logic and bootstrap their own *microarchitecture* to achieve the exploit... Absolutely stunning. https://googleprojectzero.b…
-
@itswillis
Tim Willis
on x
Finally, shoutouts to Apple and Citizen Lab, especially @radian and @jsrailton. Working together on this stuff can be complex for a number of reasons, but we made it work. Looking forward to a future post (currently being written) on the analysis of the sandbox escape. [fin]
-
@jsrailton
John Scott-Railton
on x
2/ One of the most sophisticated exploits Project Zero has ever seen. Moreover, this kind of capability was previously only seen with top tier cyber powers. Should send a chill down your spine. Underlines just how dangerous NSO & peers are. https://twitter.com/...
-
@itswillis
Tim Willis
on x
There are many companies that provide similar exploitation capabilities and services, and some more visible than others (e.g. the “US Entity List"). Taking action against one company (NSO), while noble and fosters a discussion, doesn't address the root of this problem.
-
@itswillis
Tim Willis
on x
Controls may help, but they are difficult to get right, with a high chance of constraining security research while insufficiently controlling the problem. An echo of this NSO issue is the story of HackingTeam back in 2014. https://theintercept.com/...
-
@jsrailton
John Scott-Railton
on x
3/ Recommended thread by Project Zero's @itswillis on implications of this wildly-sophisticated exploit. https://twitter.com/...
-
@josephmenn
Joseph Menn
on x
Exclusive: Wyden, Schiff and 16 others in Congress call for Magnitsky Sanctions on NSO Group and other surveillance firms. https://www.reuters.com/...
-
@jsrailton
John Scott-Railton
on x
BREAKING: senior US lawmakers call for NSO execs & peer companies to be sanctioned w/Global Magnitsky Act for facilitating torture & murder. Big names including: Senate Finance Chair @RonWyden House Intel Chair @RepAdamSchiff +16 other lawmakers. 1/ https://www.reuters.com/... ht…
-
@reuterslegal
@reuterslegal
on x
A letter by U.S. democratic lawmakers seen by Reuters asks for sanctions on top executives at cyber firm NSO and others who are accused of enabling human rights abuses including freezing bank accounts and banning travel to the U.S. https://www.reuters.com/... https://twitter.com/…
-
@silvermanjacob
Jacob Silverman
on x
NSO Group deserves everything that's coming to them, though it's an industry that extends far beyond them. https://www.reuters.com/...
-
@ronwyden
Ron Wyden
on x
I'm calling on the Biden administration to sanction hacking companies that helped tyrants target activists, journalists and political rivals. These companies must be held accountable for enabling human rights abuses by selling surveillance technology to authoritarian governments.…
-
@bing_chris
Chris Bing
on x
A significant development in the escalating battle between Washington and international digital surveillance vendors over the last year https://twitter.com/...
-
@talkopan
Tal Kopan
on x
This is notable. Wyden is a privacy hawk, but both he and Schiff are prominent Intel Committee members who don't put their names on things like this lightly. https://twitter.com/...
-
@billbrowder
Bill Browder
on x
U.S. lawmakers call for Global Magnitsky sanctions against Israel's NSO, spyware firms. Excellent initiative which should be implemented immediately. Many dead people as a result of this pernicious technology. https://www.reuters.com/...
-
@loujainhathloul
@loujainhathloul
on x
Bravo! Accountability and a safe online space is all we ask for. https://twitter.com/...
-
@rosscoulthart
Ross Coulthart
on x
Great to see this action from the US. Remember, NSO's grubby Pegasus spy software was used by the Saudis to spy on journalist Jamal Khashoggi and his family before and after he was dismembered by Saudi Govt killers. https://www.theguardian.com/ ... https://twitter.com/...
-
@davidakaye
David Kaye
on x
a @josephmenn @joel_schectman scoop on congressional call for magnitsky sanctions ag NSO Group. #Pegasus @RonWyden: “The Biden administration has the chance to turn off the spigot of American dollars and help put them out of business for good.” https://twitter.com/...
-
@dylanotes
Dylan Williams
on x
A lot going on in US-Israel relations as always, but significant, building American anger over NSO Group has potentially far-reaching implications https://twitter.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
Wyden continues to lead the push to apply the Magnitsky act against NSO Group. Schiff and 16 others join him and add DarkMatter (the UAE surveillance firm featured here https://www.nytimes.com/...) and EU surveillance companies Nexa and Trovicor to the list. https://twitter.com/.…