PWNYOURHOME
A two-stage attack involving HomeKit and iMessage, documented by Citizen Lab in 2022.
Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
- 01Year: 2022 · Platform: iOS · Vector: HomeKit + iMessage (two-stage)
- 02Interaction: Zero-click (no user interaction required)
- 03No public CVE assigned
- 04Discovered by: Citizen Lab
- 05Patched: Subsequent iOS updates
Technical Description
PWNYOURHOME involved a two-stage chain using HomeKit and iMessage components according to Citizen Lab's analysis.
Zero-Click Relevance
Zero-Click Vector
A documented two-stage zero-click chain illustrating the expanding attack surface explored by Pegasus operators.
Attribution
Attributed to Pegasus by Citizen Lab.
FORENSICALLY CONFIRMED
“PWNYOURHOME is a Pegasus exploit.”
Attributed to Pegasus by Citizen Lab.
CL-2022
What NSO Group Says
NSO Group has not publicly commented on this name.
Last Verified 2026-10-01Author Pegasus Research ArchiveEditor Editorial Team
