Pegasus Spyware Used Zero-Click iPhone Exploit Against Serbian Activist
A member of Serbia's student protest movement was infected with Pegasus spyware after receiving an iMessage exploit that required no interaction from the victim, according to a joint investigation by the Citizen Lab and the SHARE Foundation. Researchers said the exploit appears to have been patched by Apple in iOS 18.4.1, released in April 2025, but confirmed infection occurred between December 2025 and January 2026.
A zero-click exploit like this one delivers spyware without the target clicking a link or opening a file, meaning there is no visible warning sign. Once installed, Pegasus can give an attacker full access to a device, including messages, photos and notes, plus the ability to secretly activate the camera and microphone. The investigation began after the target received an Apple Threat Notification warning of mercenary spyware targeting, one of at least 14 such notifications documented among Serbian civil society members and an opposition MP ahead of 2026 elections.
Researchers noted this case fits a broader pattern of surveillance abuse in Serbia, including past Pegasus use and a separate spyware tool, NoviSpy, recently found on another activist's device. The Citizen Lab said anyone receiving an Apple Threat Notification should treat it as a likely infection and seek expert help immediately.