Trend Micro reported that the Pegasus spyware platform used a zero-click iPhone exploit known as ForcedEntry to compromise Apple devices through iMessage without requiring user interaction. The exploit chain abused how iOS processed maliciously crafted message content, allowing attackers to gain code execution and install surveillance tooling on targeted phones.
The research tied ForcedEntry to Pegasus operations and highlighted the sophistication of the attack, including its use against fully updated iPhones at the time. The findings underscored the risk posed by commercial spyware leveraging previously unknown vulnerabilities in widely deployed mobile platforms, enabling covert access to messages, calls, and other sensitive device data.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published research analyzing the ForcedEntry zero-click iPhone exploit used by Pegasus spyware, providing technical details about the exploit chain and its use against Apple devices.
Apple issued iOS 14.8 and corresponding macOS and watchOS security updates to fix CVE-2021-30860, a zero-day flaw affecting iPhones, iPads, Macs, and Apple Watches that may have been actively exploited. The patch followed Citizen Lab's discovery of ForcedEntry exploit artifacts linked with high confidence to NSO Group's Pegasus spyware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.