"A zero-click exploit requires no action from the recipient, allowing spyware to be delivered without the target clicking a link or opening an attachment," the Citizen Lab said, summarizing the delivery mechanism behind a confirmed Pegasus infection of a member of Serbia's student protest movement.
Citizen Lab and SHARE Foundation findings
The Toronto-based Citizen Lab and Belgrade's SHARE Foundation reported that forensic analysis found high-confidence indicators of NSO Group's Pegasus spyware on an individual's iPhone across December 2025 and January 2026. The target consented to publication but asked to remain unnamed, and the exact infection date was withheld to protect privacy. The laboratory emphasized that finding indicators in that window did not rule out further infections.
iMessage zero-click exploit and the iOS 18.4.1 patch
Citizen Lab's analysis concluded the attack used an iMessage zero-click exploit. The researchers said they believed the exploit had been patched by Apple as of iOS 18.4.1, a version Apple released in April 2025. The laboratory warned that zero-click infections would not have been visible to the target and would grant an attacker total device access — including notes, pictures, encrypted messages — and the covert ability to activate the microphone and camera.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildApple Threat Notifications and the scale of targeting in Serbia
The investigation began after the individual received an Apple Threat Notification warning of targeting with mercenary spyware. SHARE Foundation documented at least 14 such Apple Threat Notifications involving members of Serbia's student movement and civil society, as well as an opposition member of parliament. Citizen Lab noted that the targeting came ahead of key 2026 election cycles.
NoviSpy, Cellebrite, and a longer surveillance record
Citizen Lab placed this iPhone infection in the context of a longer history of surveillance abuses in Serbia. The laboratory cited previous Pegasus targeting of civil society and the documented use of Cellebrite forensic tools to plant NoviSpy spyware. On the same day as the Pegasus confirmation, the SHARE Foundation and Amnesty Tech confirmed that a new version of NoviSpy had been found on another member of the student movement's device.
What this means for technologists, policymakers, and activists
- Technologists and security teams should treat an Apple Threat Notification as a presumptive compromise and be prepared to provide forensic screening and remediation, consistent with Citizen Lab's guidance that such notifications should be treated as presuming infection.
- Policymakers and regulators will face pressure to examine procurement and oversight of mercenary spyware, given Citizen Lab's framing of these incidents as continued targeting of Serbia's pro-democracy movement ahead of election cycles.
- Student activists, civil-society groups, and close collaborators should expect targeted screening demands: Citizen Lab urged that close contacts such as family members and collaborators seek spyware screening and recommended that people at heightened risk enable Apple's Lockdown Mode.
Recommended actions and next steps
Citizen Lab urged recipients of Apple Threat Notifications to seek expert assistance immediately and pointed to specific resources: individuals in Serbia were encouraged to contact the SHARE Foundation; recipients elsewhere were directed to trusted experts such as Access Now's Digital Security Helpline. The laboratory also highlighted online resources including Security Planner, while stressing there is no substitute for personalized advice.
Citizen Lab said its forensic work on the other notification cases was continuing. The laboratory framed this confirmed infection as evidence of continued targeting of Serbia's pro-democracy movement with mercenary spyware — a pattern that the ongoing investigations aim to illuminate further.
Link to original story: https://www.infosecurity-magazine.com/news/pegasus-zero-click-exploit/




