A Serbian Student’s iPhone Needed No Click. Pegasus Still Got In.
The student did not tap a link, open an attachment or approve a prompt. The iPhone was still infected.
Citizen Lab has confirmed that an unnamed member of Serbia’s student protest movement was compromised with NSO Group’s Pegasus spyware through a zero-click exploit targeting iMessage. Forensic evidence placed the infection in a high-confidence window spanning December 2025 and January 2026.
That is the confirmed technical finding. It is also only one part of a much larger political surveillance story.
Pegasus crossed the phone’s boundary without a tap
The case came to light after the student received an Apple Threat Notification warning that the device may have been targeted with mercenary spyware. Citizen Lab then analysed forensic artefacts from the phone with Serbia’s SHARE Foundation.
The researchers concluded that an iMessage zero-click exploit had delivered Pegasus. No visible action by the target was required. Citizen Lab said the spyware could give its operator access to private messages, photographs, notes and other data, while also allowing the microphone and camera to be activated covertly.
The student asked to remain anonymous. Citizen Lab also withheld the exact infection date to protect the person’s privacy. That restraint matters. The public-interest finding is the verified compromise and the campaign around it, not the identity of an individual already facing intrusive surveillance.
One Pegasus infection sits inside a 14-person targeting wave
SHARE Foundation documented at least 14 people in Serbia who were targeted with advanced spyware in early 2026. The group included members of the student movement and civil society, an opposition member of parliament and a local opposition councillor.
Twelve people contacted SHARE after Apple displayed spyware warnings on their phones. The foundation said forensic work also found a new version of NoviSpy on two other devices. Citizen Lab confirmed the Pegasus infection, while Amnesty International’s Security Lab confirmed a separate NoviSpy infection.
Those facts should not be collapsed into one claim. One iPhone has a confirmed Pegasus infection. The Apple notifications are strong evidence of targeting, but they are not identical to a completed forensic confirmation on every device. NoviSpy is a separate Android spyware family with a different infection method and evidence trail.
The missing attribution is still important
Citizen Lab’s brief confirms the malware and infection method. It does not publicly identify the Pegasus operator responsible for this specific compromise. Apple threat notifications indicate targeting by mercenary spyware associated with state actors, but they do not identify the operator behind a particular case.
There is, however, a documented surveillance history in Serbia. Amnesty International reported in 2024 that Serbian authorities had used invasive surveillance tools against journalists, activists and members of civil society. That investigation described Pegasus targeting, misuse of Cellebrite phone-extraction technology and NoviSpy infections linked through technical evidence to Serbian state infrastructure.
This history makes the new case strategically significant, but it does not remove the need for evidentiary discipline. The confirmed infection, the wider targeting wave and past attribution findings can be placed beside each other. They should not be blended into an attribution that the new forensic report does not make.
The exploit may be closed. The surveillance problem is not.
Citizen Lab believes the zero-click exploit used in this case was rendered ineffective by Apple as of iOS 18.4.1. Apple released that update in April 2025 and disclosed two fixes for vulnerabilities reportedly used in sophisticated attacks against specifically targeted individuals. Citizen Lab did not publicly identify the exploit chain or link this Pegasus infection to either vulnerability.
The chronology is striking: Apple released iOS 18.4.1 months before the forensic infection window. Citizen Lab does not state which iOS version the target was running, so the public evidence does not explain why the device remained vulnerable. The safe conclusion is narrow: current iOS versions contain a fix that the researchers believe blocks this attack path. That does not reveal who ran the operation, what information was taken or whether other devices were compromised through different routes.
This is the same patch-window problem seen across mobile security. A vendor can close the technical opening while the target remains exposed to a capable operator with other exploits, account-compromise options and physical-access opportunities. BlackTree has previously examined how Apple backported newer security fixes as the patch window compressed. Mercenary spyware turns that window into a contest between small groups of highly targeted users and operators prepared to spend heavily for access.
What people at elevated risk should do
For most iPhone owners, the immediate action is simple: keep iOS updated. For journalists, activists, political organisers, opposition figures and others who may face targeted surveillance, ordinary consumer-security advice is not enough.
- Treat an Apple Threat Notification as a serious incident, not as a generic warning.
- Contact a trusted digital-security organisation immediately and preserve the device for expert forensic assistance.
- Ask close contacts and collaborators to seek advice as well, because a surveillance operation may target the surrounding network rather than one person.
- Enable Apple’s Lockdown Mode if your work or position makes mercenary-spyware targeting plausible.
- Keep the operating system and applications current, even when no technical details about an exploit are yet public.
Citizen Lab directs people outside Serbia to Access Now’s Digital Security Helpline. People in Serbia who receive a warning can contact SHARE Foundation.
The real security boundary was democratic participation
Pegasus is often discussed as an exceptional exploit reserved for exceptional targets. That framing can obscure what the operator is actually trying to reach. In this case, the phone was a route into political communication, organising, personal relationships and the private life of someone participating in a protest movement.
The strategic lesson is not simply that iMessage had a vulnerability. It is that a device can be fully patched today and still hold evidence of a campaign conducted months earlier. Closing the exploit is necessary. Establishing who authorised the surveillance, what was collected and whether legal safeguards functioned is a different job, and it begins after the patch has already shipped.
For Serbia’s civil society, that accountability gap is now the larger unresolved vulnerability.
Sources and further reading
- Citizen Lab: Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist, published 2 September 2026.
- SHARE Foundation: students and opposition politicians targeted by spyware, published 2 September 2026.
- Amnesty International: A Digital Prison, surveillance and the suppression of civil society in Serbia, published 16 December 2024.
- Apple: security content of iOS 18.4.1 and iPadOS 18.4.1, released 16 April 2025.


