Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Pegasus Spyware in 2026: The Current State of Zero-Click Exploits

Pegasus remains the most thoroughly documented mobile surveillance tool in the public record. As of 2026, its defining capability, the zero-click exploit, continues to define the asymmetry between commercial spyware operators and mobile operating systems. This article consolidates the current state from forensic reports, court filings, and peer-reviewed technical analysis.

Forensic cybersecurity lab analyzing a smartphone for Pegasus spyware

What Is Pegasus Spyware in 2026?

Pegasus is a commercial spyware suite developed by NSO Group, an Israeli cyber-intelligence company headquartered in Herzliya. As of 2026, it remains the most thoroughly documented mobile surveillance tool in the public record. Its defining capability is the zero-click exploit: a delivery method that compromises a target's iPhone or Android device without any interaction from the victim. No tap, no link, no attachment opened. The spyware arrives silently through channels the operating system itself trusts.

This article consolidates the current state of Pegasus as understood from forensic reports, court filings, and peer-reviewed technical analysis published between 2021 and early 2026. It is written for security researchers, incident responders, and policy analysts who need an evidence-grounded reference rather than a headline summary.

The Zero-Click Problem

A zero-click attack exploits a vulnerability in code that automatically processes untrusted input. On iOS, the historically dominant vector has been iMessage, whose message-processing pipeline parses rich content, images, and attachments in the background before a user ever sees a notification. NSO Group's FORCEDENTRY exploit (CVE-2021-30860), analyzed in detail by Citizen Lab and Google Project Zero in 2021, demonstrated that a specially crafted PDF could trigger a logic vulnerability in Apple's image format parser, leading to arbitrary code execution. The victim received nothing visible. The device was compromised the moment the message arrived.

By 2026, the zero-click landscape has shifted in two directions. First, Apple has hardened iMessage with BlastDoor, a sandboxed service introduced in iOS 14 that sanitizes incoming message attachments before they reach the main system. Second, NSO Group and competitors have diversified into other zero-click surfaces: WhatsApp call setup, HomeKit invitations, and push notification handlers. The BLASTPASS exploit chain (CVE-2023-41064), documented by Citizen Lab in September 2023, demonstrated a zero-click iMessage exploit that was still effective against fully patched iOS 16.6 devices, proving that the cat-and-mouse cycle between offensive researchers and platform vendors had not ended.

Documented Capability Set

Forensic analysis of Pegasus-infected devices, conducted by Amnesty International's Security Lab and Citizen Lab, has established the following capability set with high confidence:

  • Full file system access. Pegasus can read and exfiltrate files from the device, including Signal and WhatsApp message databases that are themselves encrypted at rest.
  • Real-time location tracking. GPS, Wi-Fi, and cell-tower data are collected and transmitted to the operator.
  • Microphone and camera activation. These can be triggered remotely without any on-screen indicator.
  • Keystroke and password capture. Pegasus intercepts input before it reaches encrypted containers.
  • Encrypted messaging bypass. Pegasus reads message content from the application's memory or local database after decryption, defeating end-to-end encryption without breaking the encryption itself.

This last point is critical and often misunderstood. Pegasus does not break Signal's encryption. It compromises the endpoint, reading plaintext after the application has decrypted it. End-to-end encryption is irrelevant when the endpoint is fully controlled.

Attribution and the Customer Model

NSO Group operates a sovereign-customer business model. It does not operate Pegasus itself; it licenses the platform to government intelligence and law enforcement agencies. The Pegasus Project investigation in July 2021, a collaborative effort by Forbidden Stories and 17 media organizations using a leaked list of more than 50,000 phone numbers, established that the customers included Saudi Arabia, the United Arab Emirates, Morocco, Mexico, Hungary, India, and others. Subsequent forensic work confirmed infections on devices belonging to journalists, human rights defenders, lawyers, and political opposition figures.

NSO Group has consistently maintained that its products are sold only to vetted government customers for legitimate law enforcement and counter-terrorism purposes. Multiple independent investigations have documented use against civil society targets, a finding that contributed to the U.S. Department of Commerce adding NSO Group to the Entity List in November 2021, restricting the company's access to American technology.

Where Things Stand in 2026

Three developments define the current period. First, Apple's litigation against NSO Group, filed in November 2021, continues to work through the U.S. legal system, with NSO Group's sovereign immunity defense rejected by the Ninth Circuit. Second, the EU PEGA Committee's final report, adopted in 2023, called for a moratorium on the sale and use of commercial spyware across the European Union. Third, the detection ecosystem has matured: Amnesty's MVT (Mobile Verification Toolkit) and Apple's own threat notification program now provide at least partial visibility into Pegasus activity for high-risk users.

The central problem remains unsolved. Zero-click exploits target the parsing of untrusted input, and as long as mobile operating systems automatically process rich content from untrusted senders, the attack surface exists. Lockdown Mode, Apple's opt-in hardening feature introduced in iOS 16, reduces this surface but does not eliminate it, and it imposes usability trade-offs that most users will not accept. The asymmetry between a well-funded offensive team and a general-purpose operating system remains the structural condition that makes Pegasus possible.

Sources and Further Reading

  • Citizen Lab, FORCEDENTRY: NSO Group iMessage Zero-Click Remote Exploit in the Wild, August 2021.
  • Google Project Zero, Ian Beer, Discussion of FORCEDENTRY, September 2021.
  • Citizen Lab, BLASTPASS: iPhone Zero-Click Exploit Captured in the Wild, September 2023.
  • Amnesty International Security Lab, Forensic Methodology Report, March 2022.
  • Pegasus Project, Forbidden Stories, July 2021.
  • U.S. Department of Commerce, Entity List addition, November 2021.
#pegasus spyware#zero-click#nso group#forcedentry#blastpass#ios security
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more