An iMessage with no user interaction installed Pegasus and exposed private messages, files, the microphone, and the camera.
The demonstrated access was tied to a Pegasus operator.
Apple iPhones running an iOS build vulnerable to the undisclosed iMessage chain
Zero-click installation of Pegasus with access to private data, encrypted messages, microphone and camera
Forensic evidence confirmed that a no-interaction iMessage chain installed Pegasus, which could access files, private and encrypted messages, the microphone, and the camera.
Detail and 3 sources
The operator only had to address the target through iMessage. Exploit content arrived without an open or acknowledgment, executed the undisclosed chain, and installed Pegasus.
Once installed, Pegasus could reach files, private and encrypted messages, the microphone, and the camera.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Revocation complete
- Yes
Signing-status findings reflect the pages checked on 2026-09-02; the undisclosed affected-device and version range limits the final capability conclusion.