Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

Pegasus Exploit Database

A catalog of publicly documented Pegasus exploit chains, from the 2016 one-click Trident to the 2025–2026 iMessage zero-click infection in Serbia. Each entry distinguishes one-click from zero-click and links to its primary source. This database documents history and architecture for defensive understanding — it does not contain exploit code or weaponization instructions.

ExploitYearVectorPlatformInteractionPatchedDiscovered By
Trident2016SMS link (one-click)iOSREPORTEDYesCitizen Lab / Lookout
WhatsApp 20192019WhatsApp calling infrastructurecross-platformFORENSICALLY CONFIRMEDYesWhatsApp / Citizen Lab
KISMET2020iMessageiOSFORENSICALLY CONFIRMEDYesCitizen Lab
FORCEDENTRY2021iMessageiOSFORENSICALLY CONFIRMEDYesCitizen Lab
HOMAGE2022iMessage (zero-click capability)iOSFORENSICALLY CONFIRMEDYesCitizen Lab
FINDMYPWN2022iMessage / FindMyiOSFORENSICALLY CONFIRMEDYesCitizen Lab
PWNYOURHOME2022HomeKit + iMessage (two-stage)iOSFORENSICALLY CONFIRMEDYesCitizen Lab
BLASTPASS2023PassKit / iMessageiOSFORENSICALLY CONFIRMEDYesCitizen Lab
Serbia 2025-2026 (iMessage zero-click)2025iMessageiOSFORENSICALLY CONFIRMEDYesCitizen Lab
2016REPORTED

Trident

Three iOS vulnerabilities used together to compromise the device of human rights defender Ahmed Mansoor via a malicious SMS link. Historically critical to Pegasus, but it required the target to click a link and was not the later zero-click model.

2019FORENSICALLY CONFIRMED

WhatsApp 2019

A zero-click vulnerability in WhatsApp's voice-calling infrastructure allowed a device to be compromised by a specially crafted call, even if the recipient did not answer. WhatsApp reported approximately 1,400 users were targeted during the documented attack period.

2020FORENSICALLY CONFIRMED

KISMET

An iMessage-based zero-click exploit chain documented by Citizen Lab, active in the iOS 13 era. Its disclosure informed Apple's later BlastDoor security architecture for iMessage.

2021FORENSICALLY CONFIRMED

FORCEDENTRY

A zero-click, zero-day iMessage exploit captured by Citizen Lab and reported to Apple. Amnesty researchers used the term 'Megalodon' in related analysis. Apple issued emergency patches.

2022FORENSICALLY CONFIRMED

HOMAGE

A zero-click capability identified during the CatalanGate research, affecting older iOS versions. Citizen Lab distinguished forensic evidence of HOMAGE from speculation about its full scope.

2022FORENSICALLY CONFIRMED

FINDMYPWN

A 2022-era Pegasus zero-click chain documented in Citizen Lab's 'Triple Threat' research.

2022FORENSICALLY CONFIRMED

PWNYOURHOME

A two-stage attack involving HomeKit and iMessage, documented by Citizen Lab in 2022.

2023FORENSICALLY CONFIRMED

BLASTPASS

A zero-click, zero-day exploit chain targeting PassKit and iMessage, documented by Citizen Lab on an iPhone running iOS 16.6. Apple released a security patch (iOS 16.6.1).

2025FORENSICALLY CONFIRMED

Serbia 2025-2026 (iMessage zero-click)

Citizen Lab confirmed a Pegasus infection of a Serbian student activist with high-confidence evidence across December 2025 to January 2026, assessing that an iMessage zero-click vector was used. The relevant vulnerability was subsequently patched as of iOS 18.4.1.

A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more