Home/Zero-Click Attack Intelligence
AI Summary

Zero-click attacks exploit software vulnerabilities to compromise devices without any user interaction. This intelligence analysis covers documented zero-click exploits including FORCEDENTRY and KISMET, the technical mechanics of zero-click exploitation, and defense strategies for high-risk environments.

Key Takeaways
Zero-click attacks require zero user interaction — no link to click
Delivered through messaging apps, network traffic, or media processing
FORCEDENTRY exploit compromised fully patched iPhones in 2021
No conventional security tool can prevent zero-click exploitation
Defense requires reducing attack surface, not just security awareness
Cyber Intelligence

Zero-Click Attack Intelligence

Last updated: April 2026

Zero-click attacks represent the most dangerous category of mobile exploitation — they require no action from the target, cannot be prevented through security awareness training, and are extremely difficult to detect. This intelligence analysis examines the mechanics, documented examples, and defensive implications of zero-click exploitation.

The Zero-Click Concept

A zero-click attack exploits a vulnerability in how software processes incoming data — data the device receives and handles automatically, without any user decision. Every time your phone receives a message, image, email, or phone call, software runs to process that incoming data. If that software contains a vulnerability, a specially crafted incoming item can trigger code execution before you ever see or interact with it.

FORCEDENTRY: The Most Documented Zero-Click

FORCEDENTRY, discovered by Citizen Lab in September 2021, is the most technically analyzed zero-click exploit in public record. It targeted a vulnerability in Apple's JBIG2 image compression handling library used by iMessage. NSO Group exploited this vulnerability to install Pegasus on iPhones running iOS 14.7.1 — the latest available version at the time — through a specially crafted PDF disguised as a GIF, sent as an iMessage attachment that never appeared in the message thread.

KISMET: The 2020 iPhone Zero-Click

KISMET, documented by Citizen Lab in 2020, targeted iOS 13.x devices through a zero-click iMessage vulnerability. This exploit chain was used to compromise the phones of 36 Al Jazeera journalists. The KISMET exploit left no visible trace and exploited a vulnerability in iMessage's data processing pipeline that Apple patched in iOS 14 — though NSO Group subsequently developed FORCEDENTRY to bypass the new protections.

The WhatsApp Zero-Click (2019)

A critical vulnerability in WhatsApp's VoIP stack (CVE-2019-3568) allowed Pegasus installation through a missed call. The exploit worked by sending a specially crafted call request — not even requiring the target to answer. WhatsApp logged approximately 1,400 affected users across 20 countries. The company patched the vulnerability in May 2019 and subsequently filed a lawsuit against NSO Group.

Defending Against Zero-Click Attacks

Conventional security measures cannot prevent zero-click exploitation because they rely on some form of user action to be effective — and zero-click attacks require none. Effective defense must focus on reducing the attack surface: enabling iOS Lockdown Mode (which restricts iMessage functionality and significantly reduces the attack surface), using dedicated devices that have minimal applications installed, avoiding use of consumer devices for high-sensitivity communications, and implementing air-gapped communications infrastructure for the most sensitive interactions.

Frequently Asked Questions

Request Intelligence Consultation

RedSec LTD's intelligence team provides tailored threat assessments, strategic defensive guidance, and secure communications architecture for governments, enterprises, and high-risk individuals.

VERIFIED PROTOCOLS

Trusted Discretion & Industry Authority

Operational standards that govern every engagement we undertake

Absolute Discretion
Zero-disclosure operations protocol
Encrypted Communications
End-to-end secured channels only
EU Registered Entity
Tallinn, Estonia — regulated jurisdiction
Intelligence Veterans
Decades of combined field experience
Need-to-Know Access
Compartmentalized case handling
Global Operations
Cross-jurisdictional capability
Private Intelligence

RedSec LTD

Address

Valukoja 8,
11415 Tallinn, Estonia