Critical // CRITICAL CVE-2023-41064

Blastpass Zero-Click Exploit Chain in iOS Deploying Pegasus Spyware via PassKit

Published by Tech Mentor Threat Intelligence Team
// Technical Threat Dossier
Vulnerability ID (CVE ID): CVE-2023-41064
Estimated Severity Level: Critical // CRITICAL
Affected Systems & Software: Apple iOS & iPadOS (iPhone and iPad devices)
Patch / Update Availability: 2023-09-07

Threat Scope & Field Impact:

Citizen Lab uncovered a critical zero-click, zero-day exploit chain in Apple’s ImageIO library, actively weaponized by NSO Group to infect devices belonging to civil society members with Pegasus spyware.

The attack requires zero interaction from the victim; maliciously crafted attachments containing PassKit images are sent via iMessage, causing buffer overflow and remote code execution immediately upon receipt without the user ever opening the message.

Recommended Mitigation & Action:

  • Immediate Update: Upgrade iPhone devices to iOS 16.6.1 or iOS 17 immediately via Settings > General > Software Update.
  • Enable Lockdown Mode: We strongly advise all journalists and human rights defenders in high-risk environments to enable Apple Lockdown Mode, which successfully neutralizes this exploit family.
⚡ Do you suspect you are being targeted by this exploit?

Helpline team is on standby to provide diagnosis and digital triage free of charge with complete confidentiality.

Open Emergency Helpline Ticket →