Apple v. NSO Group
In November 2021, Apple sued NSO Group in US federal court for targeting Apple users with FORCEDENTRY, a zero-click iMessage exploit. Apple sought an injunction to prevent future use of its products and services for targeting, as well as damages.
- 01Apple sued NSO Group in November 2021 in the Northern District of California
- 02The lawsuit was triggered by the FORCEDENTRY zero-click iMessage exploit (CVE-2021-30860)
- 03Apple sought a permanent injunction and damages for targeting its users
- 04Apple also created a $10 million cybersecurity fund for civil society organizations
- 05The case followed the precedent set by WhatsApp v. NSO Group (Ninth Circuit ruling)
Background
In September 2021, Citizen Lab published a report documenting FORCEDENTRY, a zero-click iMessage exploit used by NSO Group to deliver Pegasus. The exploit used a vulnerability in Apple's PDF rendering library (CVE-2021-30860, a CoreGraphics integer overflow) to execute arbitrary code on the target's iPhone when a specially crafted PDF was received and automatically processed by iMessage.
FORCEDENTRY was particularly significant because it bypassed BlastDoor, the sandboxed iMessage parsing service Apple had introduced in iOS 14 specifically to contain iMessage exploits. FORCEDENTRY exploited a vulnerability in the PDF library used within BlastDoor itself.
The Lawsuit
On November 23, 2021, Apple filed a lawsuit against NSO Group in the US District Court for the Northern District of California. The complaint alleged:
- Violation of the Computer Fraud and Abuse Act (CFAA): NSO allegedly accessed Apple's servers and users' devices without authorization
- Violation of California's Comprehensive Computer Data Access and Fraud Act
- Breach of contract: NSO allegedly violated Apple's Terms of Service and Developer Agreement
- Trespass to chattels: NSO allegedly interfered with Apple's devices and services
- Unjust enrichment: NSO allegedly profited from abusing Apple's platform
Apple sought:
- A permanent injunction barring NSO Group from using Apple's products, services, or devices
- Damages for the harm caused
- A declaration that NSO Group's actions were unlawful
Apple's Additional Actions
In conjunction with the lawsuit, Apple took several additional actions:
- $10M cybersecurity fund: Apple donated $10 million to organizations supporting cyber-attack victims, including Citizen Lab and Amnesty Tech
- Threat Notifications expansion: Apple expanded its Threat Notification program to alert more users
- Lockdown Mode development: Apple began developing Lockdown Mode (released in iOS 16, 2022) as a direct response to mercenary spyware
- Rapid patching: Apple patched FORCEDENTRY (iOS 14.8) and continued to improve its security response capabilities
NSO Group's Response
NSO Group responded to the lawsuit by:
- Disputing Apple's allegations and the characterization of its business
- Arguing that its products were used by vetted government clients for legitimate purposes
- Moving to dismiss the lawsuit on grounds similar to those raised in WhatsApp v. NSO (sovereign immunity, political question doctrine)
- Arguing that Apple's claims were precluded by the CFAA's terms and NSO's relationship with foreign governments
Current Status
The case has been proceeding through the US federal court system. Following the Ninth Circuit's ruling in WhatsApp v. NSO Group (which rejected NSO's sovereign immunity defense), Apple's case gained stronger footing. The case has been in discovery, with Apple seeking internal NSO Group documents related to FORCEDENTRY and its targeting of Apple users.
As of October 2026, the case remains ongoing. It represents one of the most significant legal actions by a technology platform against a spyware vendor, alongside WhatsApp v. NSO Group.
Significance
- Platform accountability: Demonstrated that technology platforms will actively defend their users against spyware vendors
- Financial commitment: Apple's $10M fund signaled a long-term commitment to supporting victims of cyber-attacks
- Product development: Led directly to the development of Lockdown Mode and expanded Threat Notifications
- Legal precedent: Built on and reinforced the WhatsApp v. NSO precedent for holding spyware vendors accountable
- Industry signal: Sent a clear signal to the commercial spyware industry that targeting Apple users carries legal risk
Relationship to FORCEDENTRY
The Apple v. NSO lawsuit was directly triggered by the discovery of FORCEDENTRY. See the FORCEDENTRY exploit record for technical details on the vulnerability and its exploitation.
