Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

FORCEDENTRY

A zero-click, zero-day iMessage exploit captured by Citizen Lab and reported to Apple. Amnesty researchers used the term 'Megalodon' in related analysis. Apple issued emergency patches.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Year: 2021 · Platform: iOS · Vector: iMessage
  • 02Interaction: Zero-click (no user interaction required)
  • 03CVEs: CVE-2021-30860
  • 04Discovered by: Citizen Lab
  • 05Patched: Apple iOS 14.8 / iOS 15.0.2

Technical Description

FORCEDENTRY used a maliciously crafted PDF processed by iMessage (via a CoreGraphics integer overflow) to achieve sandbox escape and code execution without user interaction.

Zero-Click Relevance

Zero-Click Vector

A landmark zero-click, zero-day case against then-current iOS, demonstrating zero-click capability against fully patched devices before vendor fixes.

Vulnerabilities

CVEStatus
CVE-2021-30860Patched

Attribution

Attributed to a Pegasus operator by Citizen Lab.

FORENSICALLY CONFIRMED

“FORCEDENTRY is a Pegasus exploit.”

Attributed to a Pegasus operator by Citizen Lab.

CL-2021-09-13

What NSO Group Says

NSO Group has not publicly confirmed individual exploit names and maintains that its technology is used for legitimate purposes.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more