Patch
Pegasus (NSO) uses targeted zero-day chains, often zero-click via iMessage:
- 2016 Trident: CVE-2016-4655 (kernel leak), -4656 (kernel corruption/jailbreak), -4657 (WebKit). SMS link (one-click).
- 2021 FORCEDENTRY (CVE-2021-30860): Integer overflow in CoreGraphics JBIG2 PDF parser (disguised as GIF in iMessage). Turing-complete logic via refinement ops.
- 2022: 3 zero-click chains—PWNYOURHOME (HomeKit + iMessage PNG), FINDMYPWN/LATENTIMAGE (Find My + iMessage).
- 2023: WebP heap overflow (CVE-2023-4863/-41064) via images.
- 2025+: WebKit/kernel zero-days (e.g. CVE-2025-43529/-14174).
Patched fast by Apple; update + Lockdown Mode mitigates.
Post summary
The post enumerates several CVEs exploited by Pegasus, details their technical nature, and notes that Apple promptly patched them with updates and Lockdown Mode.