Skip to finding
§
Medium
Mobile — zero-click
Confirmed

An iMessage with no user interaction installed Pegasus and exposed private messages, files, the microphone, and the camera.

The demonstrated access was tied to a Pegasus operator.

Affects

Apple iPhones running an iOS build vulnerable to the undisclosed iMessage chain

What it enables

Zero-click installation of Pegasus with access to private data, encrypted messages, microphone and camera

The operator selects an iMessage-reachable target→↓The target receives exploit content without interacting→↓The undisclosed iMessage chain executes and installs Pegasus→↓Pegasus accesses files, private and encrypted messages, and the microphone and camera
Why this matters

Forensic evidence confirmed that a no-interaction iMessage chain installed Pegasus, which could access files, private and encrypted messages, the microphone, and the camera.

Detail and 3 sources
Required access

A Pegasus operator able to address the victim through iMessage; the victim need not open or acknowledge anything

Affected versions

Fixed as of iOS 18.4.1; Citizen Lab did not disclose the lower bound, device model or exact vulnerable builds

Proof of concept

Demonstrated by the researcher

The operator only had to address the target through iMessage. Exploit content arrived without an open or acknowledgment, executed the undisclosed chain, and installed Pegasus.

Once installed, Pegasus could reach files, private and encrypted messages, the microphone, and the camera.

Evidence
Citizen Lab confirmed both the zero-click iMessage infection and Pegasus presence from forensic artifactsSHARE Foundation independently reported the confirmed infection and absence of user interaction
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 2, 2026