Last week, Citizen Lab discovered an actively exploited zero-click vulnerability while examining the device of an individual employed by a civil society organization based in Washington DC, which also operates internationally. This vulnerability was being utilized to deploy NSO Group's Pegasus mercenary spyware. The Exploit Chain: BLASTPASS Citezen lab dubbed this exploit chain BLASTPASS. It had the capability to compromise iPhones running the latest iOS version (16.6) without requiring any action from the victim. The exploit functioned through PassKit attachments that contained malicious images sent from an attacker's iMessage account to the victim. Citezen lab said they have plan to release a more comprehensive analysis of the exploit chain in due course. Disclosure to Apple & CVEs Citizen Lab promptly shared our discoveries with Apple and provided assistance in their investigation. Subsequently, Apple issued two CVEs pertaining to this exploit chain (CVE-2023-41064 and...