"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said.
Citizen Lab and SHARE Foundation findings
Researchers at the Citizen Lab, working with Serbia's SHARE Foundation, reported that the iPhone of a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware. The analysis identified "high-confidence indicators of infection" covering a period from December 2025 through January 2026, while noting that additional infections outside that window remain possible.
iMessage zero-click exploit and Apple patch iOS 18.4.1
The forensic assessment concluded that a zero-click exploit targeting Apple iMessage was used to deliver Pegasus. According to the report, Apple addressed the vulnerability with iOS 18.4.1, a patch the company released in April 2025. The timing of the infection window — December 2025 to January 2026 — places the compromise after that patch's release.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTargeting pattern in Serbia around the March 29, 2026 local elections
SHARE Foundation confirmed that at least 14 people in Serbia were targeted with advanced spyware since the beginning of 2026. Those targeted included members of the student movement, activists, a member of parliament, and a local councilor from opposition parties. The incidents coincided with local elections held on March 29, 2026.
NoviSpy, Cellebrite tools, and Android infections during detention
The Citizen Lab and SHARE reports situate the Pegasus finding alongside a string of documented surveillance abuses in Serbia. Another member of the student movement had their phone compromised with a new version of the NoviSpy Android spyware after their device was confiscated during police questioning. SHARE and Amnesty International’s Security Lab described this Android tool as newly built and similar in functionality to NoviSpy but with development efforts aimed at avoiding detection.
SHARE said the same spyware strain was later detected on a second device, after private Viber messages from that phone were broadcast live on Informer TV, a Serbian pro-government television channel. The reports also reference prior use of Cellebrite forensic tools in the deployment of NoviSpy.
What this means for technologists, policymakers, and at-risk users
- Technologists and security teams: forensic evidence tying a zero-click iMessage exploit to Pegasus underscores the challenge of detecting highly targeted, non-interactive compromises. The presence of a newly built Android strain designed to evade detection highlights the need for active device forensics and incident-response capabilities when devices are seized.
- Policymakers and regulators: documented targeting of politicians, opposition local officials, activists, and student organizers during an election cycle raises questions for oversight and procurement practices tied to surveillance tools. The reports point to repeated, cross-platform use of commercial and bespoke spyware in Serbia.
- At-risk users and civil-society groups: the guidance accompanying the findings emphasized practical mitigations — keep devices up-to-date and consider enabling Lockdown Mode on iOS. For Android users, Google’s Advanced Protection Program was noted as a safeguard for people with high visibility or sensitive information. Communications platforms are acting too: Meta-owned WhatsApp announced a Strict Account Settings feature that automatically locks certain account controls and blocks attachments and media from people not in a user's contacts.
The Citizen Lab and SHARE Foundation findings place a high-profile Pegasus infection alongside multiple Android compromises and a pattern of disclosure and broadcast of private messages on national television. Apple’s broad threat notifications — sent to an unspecified number of users across 110 countries — signal the global scale of mercenary spyware targeting, even as individual cases play out at the local level in Serbia.
These reports document cross-platform, targeted surveillance timed around political activity, point to the continued evolution of spyware to evade detection, and restate common defensive steps for those most at risk. They also leave open concrete operational questions: how devices were accessed during detention, how the spyware strains were procured or deployed, and what oversight exists for the forensic and offensive tools referenced. The forensic record presented by Citizen Lab and SHARE provides a snapshot; the broader policy and legal responses will determine whether it becomes a turning point or another documented episode in an ongoing pattern.
Original report: https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html




