Skip to content
PRA/Last Research Update: October 2026
Latest Developments →

Full Zero Click Pegasus Technology, Entire Source Codes & Technical Blueprints. Complete Tech Stack ₿ 0.50 BTC. Contact us.

KISMET

An iMessage-based zero-click exploit chain documented by Citizen Lab, active in the iOS 13 era. Its disclosure informed Apple's later BlastDoor security architecture for iMessage.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
  • 01Year: 2020 · Platform: iOS · Vector: iMessage
  • 02Interaction: Zero-click (no user interaction required)
  • 03No public CVE assigned
  • 04Discovered by: Citizen Lab
  • 05Patched: Subsequent iOS security updates

Technical Description

KISMET exploited iMessage processing to achieve code execution without user interaction. Citizen Lab documented its use against targets including in El Salvador (Project Torogoz).

Zero-Click Relevance

Zero-Click Vector

KISMET is a confirmed iMessage zero-click vector and a key milestone in the shift from one-click to zero-click Pegasus delivery.

Attribution

Attributed to a Pegasus operator by Citizen Lab; specific government operator not always publicly identified.

FORENSICALLY CONFIRMED

“KISMET is a Pegasus exploit.”

Attributed to a Pegasus operator by Citizen Lab; specific government operator not always publicly identified.

CL-2020-12

What NSO Group Says

NSO Group does not typically comment on individual operators or capabilities.

Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
A Spy In Your Pocket — Pegasus spyware can secretly access your photos, calls, messages, camera, microphone, GPS and more