Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.
Pegasus Exploit Database
A catalog of publicly documented Pegasus exploit chains, from the 2016 one-click Trident to the 2025–2026 iMessage zero-click infection in Serbia. Each entry distinguishes one-click from zero-click and links to its primary source. This database documents history and architecture for defensive understanding — it does not contain exploit code or weaponization instructions.
| Exploit | Year | Vector | Platform | Interaction | Patched | Discovered By |
|---|---|---|---|---|---|---|
| Trident | 2016 | SMS link (one-click) | iOS | REPORTED | Yes | Citizen Lab / Lookout |
| WhatsApp 2019 | 2019 | WhatsApp calling infrastructure | cross-platform | FORENSICALLY CONFIRMED | Yes | WhatsApp / Citizen Lab |
| KISMET | 2020 | iMessage | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
| FORCEDENTRY | 2021 | iMessage | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
| HOMAGE | 2022 | iMessage (zero-click capability) | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
| FINDMYPWN | 2022 | iMessage / FindMy | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
| PWNYOURHOME | 2022 | HomeKit + iMessage (two-stage) | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
| BLASTPASS | 2023 | PassKit / iMessage | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
| Serbia 2025-2026 (iMessage zero-click) | 2025 | iMessage | iOS | FORENSICALLY CONFIRMED | Yes | Citizen Lab |
Trident
Three iOS vulnerabilities used together to compromise the device of human rights defender Ahmed Mansoor via a malicious SMS link. Historically critical to Pegasus, but it required the target to click a link and was not the later zero-click model.
WhatsApp 2019
A zero-click vulnerability in WhatsApp's voice-calling infrastructure allowed a device to be compromised by a specially crafted call, even if the recipient did not answer. WhatsApp reported approximately 1,400 users were targeted during the documented attack period.
KISMET
An iMessage-based zero-click exploit chain documented by Citizen Lab, active in the iOS 13 era. Its disclosure informed Apple's later BlastDoor security architecture for iMessage.
FORCEDENTRY
A zero-click, zero-day iMessage exploit captured by Citizen Lab and reported to Apple. Amnesty researchers used the term 'Megalodon' in related analysis. Apple issued emergency patches.
HOMAGE
A zero-click capability identified during the CatalanGate research, affecting older iOS versions. Citizen Lab distinguished forensic evidence of HOMAGE from speculation about its full scope.
FINDMYPWN
A 2022-era Pegasus zero-click chain documented in Citizen Lab's 'Triple Threat' research.
PWNYOURHOME
A two-stage attack involving HomeKit and iMessage, documented by Citizen Lab in 2022.
BLASTPASS
A zero-click, zero-day exploit chain targeting PassKit and iMessage, documented by Citizen Lab on an iPhone running iOS 16.6. Apple released a security patch (iOS 16.6.1).
Serbia 2025-2026 (iMessage zero-click)
Citizen Lab confirmed a Pegasus infection of a Serbian student activist with high-confidence evidence across December 2025 to January 2026, assessing that an iMessage zero-click vector was used. The relevant vulnerability was subsequently patched as of iOS 18.4.1.
