Threat Scope & Field Impact:
Citizen Lab uncovered a critical zero-click, zero-day exploit chain in Apple’s ImageIO library, actively weaponized by NSO Group to infect devices belonging to civil society members with Pegasus spyware.
The attack requires zero interaction from the victim; maliciously crafted attachments containing PassKit images are sent via iMessage, causing buffer overflow and remote code execution immediately upon receipt without the user ever opening the message.
Recommended Mitigation & Action:
- Immediate Update: Upgrade iPhone devices to iOS 16.6.1 or iOS 17 immediately via Settings > General > Software Update.
- Enable Lockdown Mode: We strongly advise all journalists and human rights defenders in high-risk environments to enable Apple Lockdown Mode, which successfully neutralizes this exploit family.
