Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

BLASTPASS

A zero-click, zero-day exploit chain targeting PassKit and iMessage, documented by Citizen Lab on an iPhone running iOS 16.6. Apple released a security patch (iOS 16.6.1).

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Year: 2023 · Platform: iOS · Vector: PassKit / iMessage
  • 02Interaction: Zero-click (no user interaction required)
  • 03CVEs: CVE-2023-41064, CVE-2023-41061
  • 04Discovered by: Citizen Lab
  • 05Patched: Apple iOS 16.6.1

Technical Description

BLASTPASS used a malicious PassKit attachment delivered via iMessage, exploiting an image processing vulnerability to achieve code execution without user interaction.

Zero-Click Relevance

Zero-Click Vector

A confirmed zero-click, zero-day case against a then-current iOS version (16.6), patched promptly by Apple.

Vulnerabilities

CVEStatus
CVE-2023-41064Patched
CVE-2023-41061Patched

Attribution

Attributed to a Pegasus operator by Citizen Lab.

FORENSICALLY CONFIRMED

“BLASTPASS is a Pegasus exploit.”

Attributed to a Pegasus operator by Citizen Lab.

CL-2023-09-07

What NSO Group Says

NSO Group has not publicly confirmed the name.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more