About NSO: A Dive into Zero-Click Attack

A deep dive article – by Ian Beer & Samuel Groß of Google Project Zero – into an NSO zero-click iMessage exploit: Remote Code Execution. A fascinating example of the complexity of the digital era.

Interesting points:

  • NSO – Access-As-A-Service, packaged hacking solutions.
  • Developed a ‘super sophisticated’ method to break into iPhone called: “iMessage-based zero-click exploit” using iPhone feature + hidden weakness of the system.
  • This failure fixed September 13, 2021 in iOS 14.8
  • A fascinating example of the complexity of the digital era
  • Basic superficial explanation:
    • iPhone feature used – messages and pictures receive BEFORE the user click on it, in order to speed up service. Zero-click
    • Hidden weakness – the compressing system used in the process has a limited capacity which create a breach once reached its limit.

NSO’s “iMessage-based zero-click exploit” insert via the link instructions to initiate a breach – once the breach is achieved – take over the phone.