On May 28, 2026, Bitdefender published a retrospective that compiles historical cases of mobile spyware built on zero-day exploits, documenting how vulnerability chains for iOS and Android have become commercial products accessible to governments and potentially other buyers. The piece presents no original technical discoveries but synthesizes attack mechanisms already confirmed by independent researchers and vendors. The stakes are clear: up-to-date mobile devices protected by conventional security solutions remain exposed to infections that require no user interaction.
- Commercial spyware exploits zero-day vulnerabilities in system components — message parsers, image renderers, browser engines, kernels — to execute remote code without user interaction.
- Pegasus, developed by NSO Group, used zero-click exploits delivered via iMessage; Operation Triangulation combined multiple iOS zero-days with invisible iMessage attachments.
- Predator, linked to the Intellexa alliance, targeted both iPhone and Android, using techniques ranging from network injection to five Chrome/Android zero-days in 2021 campaigns.
- Apple introduced Lockdown Mode in 2022 as a direct response to zero-click attacks; the Google Threat Analysis Group has warned that commercial spyware vendors continue to develop sophisticated Android exploit chains.
How Zero-Click Infection Works
According to the cited source, spyware can infect phones through messages, calls, images, apps, or websites — sometimes without the victim interacting with anything. In zero-click attacks, specially crafted data triggers background code execution by exploiting flaws in messaging apps, image rendering systems, or call functions. The mechanism requires no link clicks, attachment opens, or call answers: mere receipt of the malicious data is sufficient.
The source describes this process as the evolution of spyware from an intelligence tool to a commercial product, with techniques spreading from the iOS ecosystem to Android and from phishing to pure zero-click. The significant point is not technical novelty — the cited cases are historical — but the reconstruction of a consolidated pattern.
Documented Cases: From Pegasus to Operation Triangulation
Pegasus, developed by NSO Group, used zero-click exploits delivered via Apple's iMessage service. Operation Triangulation, active in 2023, exploited multiple iOS zero-days with invisible iMessage attachments that triggered infection automatically.
According to the source, vulnerabilities CVE-2023-32434 and CVE-2023-32435 — with CVSS scores of 7.8 HIGH and 8.8 HIGH respectively per the National Vulnerability Database — were used in zero-click iMessage spyware attacks from 2019. CVE-2023-32439, also rated CVSS 8.8 HIGH, was patched by Apple and potentially actively exploited. Per Apple security release notes and Kaspersky's reconstruction cited by Bitdefender, these flaws fueled surveillance campaigns for years before official remediation.
Predator and the Expansion to Android
Predator, linked to the Intellexa alliance, targeted both Android devices and iPhones. On iOS, according to the source, it used an exploit chain with three specific vulnerabilities up to iOS 16.6.1, employing network injection techniques: in a documented case in Egypt, a device installed at the edge of the Vodafone Egypt network automatically redirected a target to a malicious website.
On Android, Predator used five Chrome/Android zero-days across three campaigns between August and October 2021. The documented CVEs are: CVE-2021-38000 (CVSS 6.1 MEDIUM per NVD), CVE-2021-37976, CVE-2021-37973, CVE-2021-1048, and CVE-2021-38003. According to the Google Threat Analysis Group, cited by Bitdefender, the zero-day exploits were used alongside n-day exploits, taking advantage of the time gap between patch release and actual deployment across the Android ecosystem.
"A single missed call. A malicious image. A hidden flaw buried deep in your phone's software. That can be enough for attackers to install spyware and read your messages, track your location, record you through the phone's camera and mic, and siphon sensitive data — without you tapping a single link." — Bitdefender HotforSecurity
Lockdown Mode and the Limits of Countermeasures
Apple introduced Lockdown Mode in 2022 as a direct response to zero-click attacks. The feature limits attack-surface components such as iMessage, FaceTime, and WebKit, reducing the likelihood of automatic exploit triggering. According to the source, Apple notified users in over 150 countries between 2021 and April 2025; in April 2024 alone it warned users in 92 countries of targeting by mercenary spyware.
The dossier does not specify, however, whether Lockdown Mode blocks all categories of documented zero-click exploits, nor does it quantify the actual risk reduction compared to interaction-required attacks. The source also reports no new zero-day cases in 2026 beyond the historical synthesis of cited cases.
Why This Matters
The Bitdefender piece presents no original research or unpublished discoveries: it is an editorial reconstruction that recompiles cases already published by other researchers and vendors. This methodological limit is relevant for reading: the dossier's value lies in the systematization of already-confirmed patterns, not in contributing new verifiable technical evidence.
The dossier does not quantify the real scale of zero-click infections relative to interaction-required attacks. It does not specify whether active spyware vendors exist in 2026 beyond NSO Group and Intellexa, nor whether Bitdefender Mobile Security specifically detects zero-click exploits or only known spyware indicators. The source documents no specific remedial measures beyond Lockdown Mode and system updates.
The concrete consequence for high-risk users — journalists, activists, executives — is that timely updates and Lockdown Mode represent partial countermeasures against a threat model that includes actors with access to commercial zero-day exploits. For the enterprise sector, the pressure remains on vendors to reduce the attack surface of components like iMessage, WebKit, and system drivers.
Frequently Asked Questions
What distinguishes a zero-click attack from one requiring interaction?
In a zero-click attack, the victim does not need to open messages, click links, or answer calls: the receipt or automatic processing of specially crafted data is sufficient to trigger the exploit.
Why are mobile devices priority targets?
According to the source, smartphones and tablets concentrate personal data, encrypted communications, location functions, and audio/video sensors, with an extended attack surface across system components often exposed to the internet.
Does the Bitdefender dossier report new 2026 vulnerabilities?
No. The May 28, 2026 piece synthesizes historical cases already documented by Kaspersky, Google TAG, Citizen Lab, and other independent researchers, without adding new CVEs or original attack campaigns.
Information is based on the cited advisory and current as of publication.
Sources
- https://www.bitdefender.com/en-us/blog/hotforsecurity/zero-day-phone-hacks-spyware-phone
- https://www.bitdefender.com/en-us/business/infozone/what-is-zero-day-vulnerability
- https://www.bitdefender.com/en-au/blog/hotforsecurity/pegasus-spyware-failed-infect-serbian-journalists-amnesty-international
- https://www.bitdefender.com/en-us/blog/hotforsecurity/what-is-lockdown-mode-iphone-mac-spyware-when-use-it
- https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-issues-emergency-updates-to-combat-triangulation-spyware
- https://www.bitdefender.com/en-us/blog/hotforsecurity/predator-spyware-operators-caught-exploiting-security-holes-now-patched-by-apple-and-google
- https://www.bitdefender.com/en-us/blog/hotforsecurity/predator-spyware-used-zero-days-to-infect-android-devices-google-says
Information is based on the cited source and current as of publication.