Citizen Lab, working with Serbia's SHARE Foundation, has confirmed that an iMessage zero-click exploit was used to install NSO Group's Pegasus spyware on the iPhone of a member of Serbia's student protest movement.
The infection ran from December 2025 into January 2026. It was made public on 3 September 2026.
The fix was already eight months old
Apple patched the vulnerability in iOS 18.4.1, released in April 2025.
So the sequence is: a fix ships, eight months pass, and the exploit still lands. Whatever else this is, it is not a story about an unstoppable capability. It is a story about a phone that was not updated, and an operator who knew that population exists.
That is the second time this week we have written the same sentence. Thirteen PHP packages ended at an iPhone kernel using a chain where every flaw was already patched, targeting iOS 18.4 through 18.6.x. Different operator, different budget, identical dependency: someone who did not install the update.
For a commercial spyware vendor this is the economically rational position. A zero-day is expensive and perishable; an n-day against an activist's phone is cheap and works for as long as the phone stays behind.
What is confirmed, and what is not
Citizen Lab says it found high-confidence indicators of Pegasus infection, and adds that this does not preclude the possibility of additional infections.
That identifies the tool. It does not identify the operator, and no CVE is named in the reporting.
NSO sells to governments. That is a fact about the vendor's business model and it is not evidence about who ran this particular operation, and the report as published names nobody. No statement from NSO Group or from the Serbian government appears in it.
We have held this line on weaker signals and it applies to stronger ones too: "Pegasus was used" and "the government used Pegasus" are different claims, and only the first one is supported here.
The wider pattern in Serbia
At least 14 people in Serbia have been targeted with advanced spyware since early 2026, around the 29 March 2026 local elections.
One detail from that set sits apart from the rest. Another student activist's device was compromised with NoviSpy Android spyware while they were in police detention — which is not a remote exploit at all. It is physical access to a seized phone.
Those are different capabilities with different evidentiary weight, and they should not be summed into one number without saying so.
The notification gap
Apple sent threat notifications in August 2026 to people in over 110 countries — we covered that round when it went out, including the point that Apple deliberately attributes nothing.
Put the dates together. Infection: December 2025 to January 2026. Apple notification: August 2026. Public forensic confirmation: September 2026.
That is roughly seven to eight months from compromise to notification, and another month to a published finding. None of that is a failure by Apple or by Citizen Lab — detection of a zero-click infection is genuinely hard and forensics take time — but it is the actual operational reality for anyone in this position. If you are a plausible target, the alert arrives long after the access did.
What to do
- Update. It is the whole defence in this case and it is free.
- Turn on Lockdown Mode if you are an activist, journalist, lawyer or opposition figure. It removes attack surface that ordinary users need and targets do not.
- If you get an Apple threat notification, treat the device as compromised from months earlier, not from the date on the message.
- Get forensics done by people who do this — Citizen Lab, Amnesty's Security Lab, Access Now's helpline — rather than wiping first and asking later. A wipe destroys the evidence that would establish what happened.
What is not established
- Who operated the spyware. The tool is identified. The customer is not.
- Which CVE was used. The reporting names the patch level, not the identifier.
- How many of the 14 Serbian cases involve Pegasus specifically, as distinct from other tooling including NoviSpy.
- Whether NSO or the Serbian government dispute any of this. Neither is quoted.
- Whether this device was infected more than once. Citizen Lab explicitly leaves that open.