THREATS AND VULNERABILITIES
BLASTPASS iPhone Zero-Click Exploit: Business Lessons

In September 2023, Citizen Lab reported that it had found an actively exploited zero-click chain while examining the iPhone of a person employed by a Washington, D.C.-based civil-society organization. The researchers named the chain BLASTPASS and attributed its use to NSO Group’s Pegasus mercenary spyware. Apple released iOS and iPadOS 16.6.1 with fixes for CVE-2023-41061 and CVE-2023-41064 and stated that both issues may have been actively exploited.
This article summarizes the public evidence at the level the sources support. OC Security Audit did not examine the device, does not independently attribute the activity, and does not reproduce exploit material. The historical version numbers are not current patch advice; verify current supported releases through Apple.
Incident summary
| Evidence source | What it establishes |
|---|---|
| Citizen Lab | Reported a zero-click chain against an iPhone running iOS 16.6, malicious PassKit attachments with images, delivery through iMessage, and attribution to NSO Group’s Pegasus |
| Apple advisory | CVE-2023-41064 affected malicious image processing; CVE-2023-41061 affected a malicious attachment; Apple said reports indicated possible active exploitation |
| OC Security Audit | Defensive analysis of update, high-risk-user, detection-limit, response, and governance lessons |
| Not established here | Full operator/customer identity, every target, complete data impact, prevalence, or every technical component used outside the reported case |
What Citizen Lab reported
Citizen Lab’s BLASTPASS report said the chain could compromise an iPhone running iOS 16.6 without victim interaction. The report described PassKit attachments containing malicious images sent from an attacker-controlled iMessage account. Citizen Lab stated that it disclosed the chain to Apple and believed Lockdown Mode blocked the attack.
Those are researcher findings from a specific investigation. They should not be expanded into a claim that all Wallet passes, all iMessages, all civil-society workers, or all iPhones were compromised. The absence of a click is central: user awareness alone could not prevent the reported delivery path.
What Apple confirmed in the advisory
Apple’s iOS 16.6.1 security advisory lists two issues:
- CVE-2023-41064, ImageIO: processing a maliciously crafted image could lead to arbitrary code execution; Apple was aware of a report that it may have been actively exploited.
- CVE-2023-41061, Wallet: a maliciously crafted attachment could result in arbitrary code execution; Apple was aware of a report that it may have been actively exploited.
Apple credited Citizen Lab for CVE-2023-41064 and acknowledged its assistance for Wallet. The advisory provides the vendor-confirmed vulnerabilities and fixed release; it does not provide a complete public account of the operator, target population, or impact.

Why zero-click changes the control balance
Many mobile-security programs focus on malicious links, application installs, and credential phishing. Those controls remain important, but a zero-click case demonstrates why organizations also need rapid vendor updates, high-risk-user protection, threat-notification response, specialist forensics, identity monitoring, and secure replacement communications.
An App Store security tool cannot freely inspect every protected iOS process or another application’s data. A clean scan or absence of an alert is not proof that sophisticated spyware is absent. The suspected iPhone spyware response guide explains when evidence preservation and specialist support may be appropriate.
Business lesson 1: make accelerated updating operational
Apple released iOS 16.6.1 on the day Citizen Lab published its report. An organization cannot rely on a monthly reminder when a credible targeted issue affects high-risk users. Define who monitors Apple advisories, who classifies exposure, who tests critical workflows, which roles receive an accelerated deadline, and how completion is verified.
Use the business iPhone update-management guide for inventory, deadline, enforcement, exception, and evidence design. Use Apple’s current security releases page for today’s supported version information.
Business lesson 2: evaluate Lockdown Mode before an incident
Citizen Lab said it believed Lockdown Mode blocked BLASTPASS. Apple describes Lockdown Mode as an extreme, optional protection for the very small number of users who may be targeted by highly sophisticated attacks. It limits features and can affect workflows.
Do not wait for a crisis to discover that an executive’s communications, attachments, shared albums, web features, or device-management process is affected. The iPhone Lockdown Mode guide covers selection, testing, support, and exception questions. Do not state that Lockdown Mode is infallible or universally required.
Business lesson 3: prepare high-risk users and support teams
Identify users with elevated targeting or business impact: executives, administrators, legal and finance leaders, journalists, political or public-interest personnel, incident responders, and certain travelers. Provide a verified contact that works without the affected iPhone. Protect account recovery, primary email, assistants, trusted devices, and administrative roles.
If Apple sends a threat notification, the user should verify it through the trusted Apple Account route and follow the Apple threat-notification response guide. A notification is an escalation signal, not public proof of a named operator or confirmed data theft.
Business lesson 4: preserve evidence without delaying safety
Citizen Lab’s report depended on access to the target device and forensic analysis. An immediate factory reset can remove useful artifacts. The response plan should let an authorized incident lead quickly decide between preservation, containment, replacement communications, and destructive remediation.
Personal safety and active exposure may require immediate action. Document the facts, source, time, device state, update build, important account activity, commands, and decision. Do not send sensitive incident details through the potentially affected device.
Business lesson 5: communicate evidence levels precisely
Executives and legal teams should distinguish:
- a vulnerability exists;
- Apple reports possible active exploitation;
- a researcher reports targeting;
- an exploit attempt reached a device;
- compromise is forensically supported; and
- data impact is established.
Collapsing those levels creates misinformation and legal risk. It can also cause the organization to erase evidence or notify stakeholders based on an unsupported conclusion.
Defensive checklist
- Maintain an accountable iPhone inventory and current build data.
- Establish accelerated deadlines for active-exploitation statements.
- Preselect high-risk users and test Lockdown Mode where appropriate.
- Provide an alternate reporting and replacement-communications path.
- Monitor Apple Account, identity, email, and sensitive application sessions.
- Preserve evidence when risk and safety permit.
- Verify current releases directly with Apple.
- Run a tabletop that includes a zero-click scenario with no suspicious user action.
The actively exploited iPhone vulnerabilities page supports ongoing prioritization. The comparative iPhone zero-click evolution guide places BLASTPASS beside FORCEDENTRY without treating two cases as the entire threat landscape.
Scope and limitations
BLASTPASS is a historical named chain, not a current detection signature for end users. This article does not establish that a reader was targeted or compromised. Do not upload potentially sensitive forensic material to an unverified website or install an unknown profile in an attempt to check.
A scoped security audit can review mobile inventory, update readiness, high-risk-user controls, identity monitoring, and incident procedures. Cybersecurity compliance consulting can help align response evidence and notification decision processes with applicable obligations, with qualified legal advice where needed.
Sources
Test readiness for attacks that require no click
OC Security Audit can review iPhone patch operations, executive protections, threat-notification handling, identity containment, and evidence-ready response. Contact OC Security Audit and learn about Ali Hassani, CISO—25+ years of cybersecurity, compliance, infrastructure, and incident leadership.
Update and correction history
- August 2026: Apple source links were revalidated and updated to current official canonical destinations; the surrounding analysis and conclusions were unchanged.
- August 2026: Initial analysis prepared from Citizen Lab, Apple, and NIST sources available through August 1, 2026.