Serbia 2025-2026 (iMessage zero-click)
Citizen Lab confirmed a Pegasus infection of a Serbian student activist with high-confidence evidence across December 2025 to January 2026, assessing that an iMessage zero-click vector was used. The relevant vulnerability was subsequently patched as of iOS 18.4.1.
- 01Year: 2025 · Platform: iOS · Vector: iMessage
- 02Interaction: Zero-click (no user interaction required)
- 03No public CVE assigned
- 04Discovered by: Citizen Lab
- 05Patched: Apple iOS 18.4.1
Technical Description
Citizen Lab assessed an iMessage zero-click vector was used; no public exploit nickname has been assigned by researchers.
Zero-Click Relevance
A 2025-2026 confirmed iMessage zero-click infection, the most recent documented zero-click case as of October 2026.
Attribution
Citizen Lab confirmed Pegasus infection; the responsible government operator was not publicly identified in the initial disclosure.
“Serbia 2025-2026 (iMessage zero-click) is a Pegasus exploit.”
Citizen Lab confirmed Pegasus infection; the responsible government operator was not publicly identified in the initial disclosure.
What NSO Group Says
NSO Group has not publicly commented on this specific case.
