Citizen Lab: Pegasus zero-click via iMessage infected Serbian student activist’s iPhone
Citizen Lab (2 September 2026), with the SHARE Foundation, confirmed that an iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware via an iMessage zero-click exploit. High-confidence indicators cover December 2025–January 2026; Citizen Lab assesses the exploit was addressed in Apple iOS 18.4.1 (April 2025). SHARE has documented at least 14 recent Apple Threat Notifications among Serbian students, civil society and an opposition MP ahead of 2026 election cycles; Amnesty has separately described related Android spyware (NoviSpy-like) installed during detention. Primary: Citizen Lab research note. Recipients of Apple Threat Notifications should treat devices as presumed targeted and seek forensic help; keep iOS current.
- Product
- Apple iPhone / iMessage (Pegasus spyware)
- Versions
- Exploit assessed patched as of iOS 18.4.1 (Apr 2025)
- Exploited in Australia?
- unknown
- Patch to
- Current iOS; treat Apple Threat Notifications as presumed targeting
Primary: Citizen Lab (2 Sep 2026) · Vendor: Citizen Lab (University of Toronto) · The Hacker News (3 Sep 2026)
