Skip to content

Zero-Click Apple Messenger Vulnerability: Critical Actions to Take

On September 13, Citizen Lab identified a zero-click exploit “in the wild” from NSO Group impacting all Apple Messenger products. This impacts all devices that use Messenger including iPhones, Mac, iPad and Apple Watches. Citizen Lab has dubbed this spyware “Forcedentry.”

Apple has issued an update to combat this vulnerability. The most important step you can take right now is to update your Apple devices to ensure you are no longer impacted. You should update to the following versions:

  • macOS Big Sur 11.6
  • iOS 14.8
  • watchOS 7.6.2

You can further protect yourself from NSO spyware domains by blocking “Trackers” on DNSFilter. DNSFilter has proactively flagged all known NSO spyware domains as “Trackers,” thanks to Amnesty International’s excellent work investigating the group. Our Domain Intelligence team identified and added these trackers to our block list on July 20th, 2021.

Blocking the Trackers category will prevent any compromised devices from sending out data to their servers.

Please note, however, that the vulnerability itself is part of Apple’s Messenger, so will continue to exist and be exploitable by other malicious actors until affected devices have been updated as per Apple’s advisory.

It is imperative to ensure your devices always contain the latest patches to protect against vulnerabilities. Today's announcement about the zero-click exploit impacting Apple devices not only highlights the importance of the patch, but also is active in the wild. If you need to bide your time before making updates across your organization, changing your DNSFilter policy to block "Trackers" will offer an additional layer of protection against this zero-click exploit.


Search
  • There are no suggestions because the search field is empty.
Latest posts
How Black Hat Proved DNSFilter is on the Right Expansion Path How Black Hat Proved DNSFilter is on the Right Expansion Path

By Ken Carnesi, CEO & Co-Founder, DNSFilter

I've been going to Black Hat for years, and I can tell you plainly: This year was different.

Shadow AI and AI governance are top of mind now, an evolution from what we were hearing at RSA earlier this year. In an AI era, taking a DNS First approach to cybersecurity isn't optional, and we're built to solve exactly that problem.

I Went to Black Hat 2026 and Only Saw the Expo Floor. Here's What I Learned. I Went to Black Hat 2026 and Only Saw the Expo Floor. Here's What I Learned.

To see what our CEO Ken Carnesi thought of the week at Black Hat, check out his blog here.

Black Hat took over Mandalay Bay this week, and the official theme was impossible to miss: AI, everywhere, all at once. The keynotes covered cyber power in the age of AI, defending when offense is cheap, and vulnerability research in the agentic age. The vendor announcements were wall-to-wall AI agents, autonomous response, and identity security. TechTarg...

DNSFilter Earns 22 Badges in G2's Summer 2026 Reports DNSFilter Earns 22 Badges in G2's Summer 2026 Reports

The G2 Summer 2026 reports are out, and DNSFilter earned 22 badges across the Grid® and index reports. Only a small fraction of the products on G2 earn a Leader badge in any given season, and this summer you named us a Leader across the overall Grid® Report, the Mid-Market Grid®, the Small-Business Grid®, and the EMEA Regional Grid®, along with Momentum Leader for ranking in the top 25% of our category.

Explore More Content

Ready to brush up on something new? We've got even more for you to discover.