FORCEDENTRY
A zero-click, zero-day iMessage exploit captured by Citizen Lab and reported to Apple. Amnesty researchers used the term 'Megalodon' in related analysis. Apple issued emergency patches.
- 01Year: 2021 · Platform: iOS · Vector: iMessage
- 02Interaction: Zero-click (no user interaction required)
- 03CVEs: CVE-2021-30860
- 04Discovered by: Citizen Lab
- 05Patched: Apple iOS 14.8 / iOS 15.0.2
Technical Description
FORCEDENTRY used a maliciously crafted PDF processed by iMessage (via a CoreGraphics integer overflow) to achieve sandbox escape and code execution without user interaction.
Zero-Click Relevance
A landmark zero-click, zero-day case against then-current iOS, demonstrating zero-click capability against fully patched devices before vendor fixes.
Vulnerabilities
| CVE | Status |
|---|---|
| CVE-2021-30860 | Patched |
Attribution
Attributed to a Pegasus operator by Citizen Lab.
“FORCEDENTRY is a Pegasus exploit.”
Attributed to a Pegasus operator by Citizen Lab.
What NSO Group Says
NSO Group has not publicly confirmed individual exploit names and maintains that its technology is used for legitimate purposes.
