BLASTPASS
A zero-click, zero-day exploit chain targeting PassKit and iMessage, documented by Citizen Lab on an iPhone running iOS 16.6. Apple released a security patch (iOS 16.6.1).
Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
- 01Year: 2023 · Platform: iOS · Vector: PassKit / iMessage
- 02Interaction: Zero-click (no user interaction required)
- 03CVEs: CVE-2023-41064, CVE-2023-41061
- 04Discovered by: Citizen Lab
- 05Patched: Apple iOS 16.6.1
Technical Description
BLASTPASS used a malicious PassKit attachment delivered via iMessage, exploiting an image processing vulnerability to achieve code execution without user interaction.
Zero-Click Relevance
Zero-Click Vector
A confirmed zero-click, zero-day case against a then-current iOS version (16.6), patched promptly by Apple.
Vulnerabilities
| CVE | Status |
|---|---|
| CVE-2023-41064 | Patched |
| CVE-2023-41061 | Patched |
Attribution
Attributed to a Pegasus operator by Citizen Lab.
FORENSICALLY CONFIRMED
“BLASTPASS is a Pegasus exploit.”
Attributed to a Pegasus operator by Citizen Lab.
CL-2023-09-07
What NSO Group Says
NSO Group has not publicly confirmed the name.
Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
