KISMET
An iMessage-based zero-click exploit chain documented by Citizen Lab, active in the iOS 13 era. Its disclosure informed Apple's later BlastDoor security architecture for iMessage.
- 01Year: 2020 · Platform: iOS · Vector: iMessage
- 02Interaction: Zero-click (no user interaction required)
- 03No public CVE assigned
- 04Discovered by: Citizen Lab
- 05Patched: Subsequent iOS security updates
Technical Description
KISMET exploited iMessage processing to achieve code execution without user interaction. Citizen Lab documented its use against targets including in El Salvador (Project Torogoz).
Zero-Click Relevance
KISMET is a confirmed iMessage zero-click vector and a key milestone in the shift from one-click to zero-click Pegasus delivery.
Attribution
Attributed to a Pegasus operator by Citizen Lab; specific government operator not always publicly identified.
“KISMET is a Pegasus exploit.”
Attributed to a Pegasus operator by Citizen Lab; specific government operator not always publicly identified.
What NSO Group Says
NSO Group does not typically comment on individual operators or capabilities.
