Skip to main content

Citzen Lab Report: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild




 Last week, Citizen Lab discovered an actively exploited zero-click vulnerability while examining the device of an individual employed by a civil society organization based in Washington DC, which also operates internationally. This vulnerability was being utilized to deploy NSO Group's Pegasus mercenary spyware.


The Exploit Chain: BLASTPASS

Citezen lab dubbed this exploit chain BLASTPASS. It had the capability to compromise iPhones running the latest iOS version (16.6) without requiring any action from the victim. The exploit functioned through PassKit attachments that contained malicious images sent from an attacker's iMessage account to the victim.


Citezen lab said they have plan to release a more comprehensive analysis of the exploit chain in due course.


Disclosure to Apple & CVEs



Citizen Lab promptly shared our discoveries with Apple and provided assistance in their investigation. Subsequently, Apple issued two CVEs pertaining to this exploit chain (CVE-2023-41064 and CVE-2023-41061).


Update Apple Devices Immediately

We strongly advise everyone to promptly update their devices. For those who may face heightened risk due to their identities or activities, we recommend enabling Lockdown Mode. According to both our assessment and confirmation from Apple’s Security Engineering and Architecture team, Lockdown Mode effectively thwarts this specific attack.


We commend Apple for their swift investigative response and patch implementation, and we extend our appreciation to the victim and their organization for their cooperation and support.


Highly Targeted Civil Society: A Cybersecurity Early Warning System

This recent discovery underscores once again that civil society remains a prime target for exceptionally sophisticated exploits and mercenary spyware. Apple’s update will safeguard devices belonging to everyday users, corporations, and governments worldwide. The BLASTPASS revelation emphasizes the immense value, in terms of collective cybersecurity, in championing civil society organizations.

Popular posts from this blog

AT&T Resets Millions of Customer Passcodes After Data Leak: What You Need to Know

AT&T recently confirmed a significant data breach affecting over 7.6 million current customers and 65 million former customers. The leaked information, which dates back to 2019 or earlier, includes personal details like names, addresses, phone numbers, and social security numbers. Fortunately, financial information and call history were not compromised. In response to the breach, AT&T has reset passcodes for affected customers. Passcodes, usually four-digit numbers, serve as an additional layer of security when accessing accounts. However, security experts warn that the encrypted passcodes leaked alongside customer information could be easily deciphered, posing a risk of unauthorized account access. Affected customers are advised to set up free fraud alerts with major credit bureaus and remain vigilant for any suspicious activity related to their accounts. AT&T is proactively reaching out to impacted customers via email or letter to inform them about the breach and the meas...

Sam Bankman-Fried sentenced to 25 years in jail for FTX fraud

FTX co-founder Sam Bankman-Fried has been sentenced to 25 years in prison for his involvement in seven counts of conspiracy and fraud related to the collapse of the cryptocurrency exchange he established. The judge handed down a sentence of 240 months for four charges and 60 months for two others, along with ordering Bankman-Fried to forfeit more than $11 billion, including property, as recommended by prosecutors. The judge's decision fell short of the 40 to 50 years requested by prosecutors, but exceeded the defense's plea for six and a half years, though it was notably less than the maximum sentence of 110 years. During the trial, it was revealed that Bankman-Fried was aware of the risks FTX faced, misused customer funds, and knowingly engaged in wrongful activities. He justified his actions by weighing the risk of getting caught against potential gains. The judge dismissed claims that customers would be reimbursed, highlighting that FTX customers suffered losses of $8 billio...

What is a VPN and why would you need one?

  Understanding VPN: A Comprehensive Guide for Beginners In today's digital age, the internet is an essential part of our daily lives. From online banking and shopping to social networking and entertainment, we rely on the internet for numerous activities. However, with the increasing reliance on the internet, concerns about online privacy and security have become more prominent. This is where a VPN comes into play. If you're unfamiliar with the term, this guide will explain what a VPN is, how it works, and why you might want to consider using one. What is a VPN? VPN stands for Virtual Private Network. It is a service that creates a secure, encrypted connection between your device (such as a computer, smartphone, or tablet) and the internet. Think of it as a private tunnel through which your data travels, hidden from prying eyes. How Does a VPN Work? When you connect to the internet without a VPN, your data travels through your Internet Service Provider (ISP) and can be potenti...