Sources: Israeli surveillance company QuaDream used the zero-click ForcedEntry exploit to break into iPhones in 2021; ForcedEntry was also used by NSO Group
A flaw in Apple's software exploited by Israeli surveillance firm NSO Group to break into iPhones in 2021 was simultaneously abused …
Context & Ripple Effects
When Citizen Lab documented ForcedEntry in August 2021, it was framed as an NSO Group capability: a zero-click iMessage chain that circumvented iOS 14's BlastDoor defense, likely deployed by Bahrain against activists. The new reporting adds a second customer for the same exploit — Tel Aviv-based QuaDream, which Citizen Lab and Microsoft later tied to hacks of journalists, politicians, and an NGO worker on iOS 14 devices.
That matters because it shows the mercenary spyware market sharing attack infrastructure rather than each vendor building alone: one vulnerability chain served at least two competing Israeli firms in the same year, extending a pattern that goes back to the 2016 zero-day flaws used against activists.
First-order effects
- Apple's BlastDoor iMessage filtering — built specifically to stop zero-click attacks — was defeated simultaneously by NSO Group and its rival QuaDream, meaning every iPhone user targeted by either vendor faced identical exposure until Apple patched.
Second-order effects
- Shared exploits compress the moat between spyware vendors: if QuaDream and NSO draw on the same exploit supply, the competitive edge shifts from technical capability to broker relationships and government client lists, and a single Apple patch degrades both firms' products at once.
Third-order effects
- If exploit chains circulate across the mercenary market as a commodity, defensive pressure concentrates entirely on platform vendors like Apple — whose response cadence, from the 2016 patch through the successive zero-click fixes of 2022, becomes the real control point — and regulators face an industry where attribution of any single hack no longer identifies a single vendor.
The trend: Mercenary iPhone spyware is consolidating around shared zero-click exploit chains, making Apple's patch cycle and exploit-broker networks the structural chokepoints of the surveillance market.