Zero-click attacks exploit software vulnerabilities to compromise devices without any user interaction. This intelligence analysis covers documented zero-click exploits including FORCEDENTRY and KISMET, the technical mechanics of zero-click exploitation, and defense strategies for high-risk environments.
Zero-click attacks represent the most dangerous category of mobile exploitation — they require no action from the target, cannot be prevented through security awareness training, and are extremely difficult to detect. This intelligence analysis examines the mechanics, documented examples, and defensive implications of zero-click exploitation.
A zero-click attack exploits a vulnerability in how software processes incoming data — data the device receives and handles automatically, without any user decision. Every time your phone receives a message, image, email, or phone call, software runs to process that incoming data. If that software contains a vulnerability, a specially crafted incoming item can trigger code execution before you ever see or interact with it.
FORCEDENTRY, discovered by Citizen Lab in September 2021, is the most technically analyzed zero-click exploit in public record. It targeted a vulnerability in Apple's JBIG2 image compression handling library used by iMessage. NSO Group exploited this vulnerability to install Pegasus on iPhones running iOS 14.7.1 — the latest available version at the time — through a specially crafted PDF disguised as a GIF, sent as an iMessage attachment that never appeared in the message thread.
KISMET, documented by Citizen Lab in 2020, targeted iOS 13.x devices through a zero-click iMessage vulnerability. This exploit chain was used to compromise the phones of 36 Al Jazeera journalists. The KISMET exploit left no visible trace and exploited a vulnerability in iMessage's data processing pipeline that Apple patched in iOS 14 — though NSO Group subsequently developed FORCEDENTRY to bypass the new protections.
A critical vulnerability in WhatsApp's VoIP stack (CVE-2019-3568) allowed Pegasus installation through a missed call. The exploit worked by sending a specially crafted call request — not even requiring the target to answer. WhatsApp logged approximately 1,400 affected users across 20 countries. The company patched the vulnerability in May 2019 and subsequently filed a lawsuit against NSO Group.
Conventional security measures cannot prevent zero-click exploitation because they rely on some form of user action to be effective — and zero-click attacks require none. Effective defense must focus on reducing the attack surface: enabling iOS Lockdown Mode (which restricts iMessage functionality and significantly reduces the attack surface), using dedicated devices that have minimal applications installed, avoiding use of consumer devices for high-sensitivity communications, and implementing air-gapped communications infrastructure for the most sensitive interactions.
Operational standards that govern every engagement we undertake
Valukoja 8,
11415 Tallinn, Estonia