Google Project Zero described FORCEDENTRY, an NSO Group exploit delivered through iMessage on iPhones, as “one of the most technically sophisticated exploits” its researchers had seen. The zero-click attack used a PDF disguised as a GIF to reach Apple’s image-processing code, where a vulnerability allowed the exploit to advance toward sandbox escape and remote code execution. Apple fixed the vulnerability, CVE-2021-30860, in iOS 14.8 in September 2021.
What was Pegasus FORCEDENTRY?
FORCEDENTRY was an NSO Group exploit chain used to deliver Pegasus spyware to iPhones. Citizen Lab recovered it from an iPhone and documented its use against a Saudi activist. Google Project Zero researchers Ian Beer and Samuel Groß analyzed the exploit and assessed that it was “one of the most technically sophisticated exploits we’ve ever seen.” Their assessment concerned the iPhone exploit they analyzed; Project Zero said it did not have a sample of the analogous Android exploit.
The wording matters: Google called FORCEDENTRY one of the most sophisticated exploits its researchers had seen, not the single most sophisticated exploit ever made. The assessment described the ingenuity of this particular chain, not every Pegasus operation or every way NSO could target a device.
How could an iPhone be attacked without a click?
A zero-click exploit does not require the target to tap a link, open an attachment, or take another action to trigger the vulnerability. FORCEDENTRY used iMessage as its delivery surface. An attacker could select a target using a phone number or Apple ID username, and the iPhone automatically processed incoming image content as part of handling the message—before the recipient saw it.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
That automatic processing was central to the attack: the malicious content could reach vulnerable parsing code without the recipient opening a message or file. Project Zero warned that there is no practical user action that reliably prevents exploitation by a zero-click exploit once a device is exposed to one. That observation describes the difficulty of defending against this class of attack; it does not mean that every iPhone message is malicious or that every device can be exploited at all times.
What made the fake GIF and JBIG2 technique unusual?
A PDF wearing a GIF filename
The incoming file was crafted to look like a GIF based on its filename, but its contents were a PDF. Apple’s ImageIO and CoreGraphics frameworks processed the content, and the PDF included image data encoded with JBIG2. The mismatch helped the exploit reach the relevant PDF and image-processing code through a message that the device handled automatically.
Image-compression operations built a small computer
JBIG2 is an image format, but its logical operations can be combined to perform computation. Project Zero found that the exploit used more than 70,000 JBIG2 segment commands to construct a small computer architecture, including registers and a full 64-bit adder and comparator. The exploit used that improvised machine to search memory and perform arithmetic.
Project Zero said the result was “fundamentally computationally equivalent” to a computer, though not as fast as JavaScript. The exploit’s bootstrapping code ran within this constructed environment and then continued toward sandbox escape and remote code execution. The sophistication lay not simply in finding a software bug, but in using image-format operations to create a computational environment that helped the attack progress.
Recommended Free Tools
What did Apple patch in iOS 14.8?
The key vulnerability was CVE-2021-30860, a flaw in CoreGraphics handling of JBIG2 content in PDFs. Google’s later review of in-the-wild exploits characterized the underlying bug as a classic integer overflow. That distinction helps explain Google’s praise: the vulnerability itself was not the technically exceptional part; the exploit’s method of using it was.
Project Zero records that Apple fixed CVE-2021-30860 in iOS 14.8, released September 13, 2021. Apple also hardened related processing paths afterward:
- iOS 14.8: Fixed CVE-2021-30860.
- iOS 14.8.1: Restricted the ImageIO formats reachable through the relevant path.
- iOS 15: Removed the GIF path from IMTranscoderAgent and moved GIF decoding into the BlastDoor isolation layer.
These later changes reduced exposure in the processing path; they are distinct from the initial vulnerability fix in iOS 14.8.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why did Google consider the exploit significant?
FORCEDENTRY combined several difficult stages: a message processed without user interaction, a disguised document, a parser vulnerability, a custom virtual machine assembled from image-compression operations, and logic intended to move beyond the initial processing environment. Project Zero said the chain demonstrated that commercial surveillance vendors could field capabilities previously associated with only a small number of nation-states.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
Google’s 2022 review of in-the-wild exploits also identified FORCEDENTRY as one of only two 2021 zero-days that stood out for technical sophistication. The finding is about the capability shown by this exploit, not a measure of how frequently it succeeded. The cited analysis does not establish a reliable total of victims, development cost, or general success rate.
Quick Recap
What the finding does—and does not—show
- FORCEDENTRY was an NSO Group Pegasus delivery chain targeting iMessage on iPhones.
- It was zero-click: the recipient did not have to interact with the malicious message to trigger processing.
- A PDF disguised by a .gif filename reached CoreGraphics/JBIG2 handling code.
- More than 70,000 JBIG2 segment commands were used to implement a small computational architecture inside the exploit.
- The vulnerability, CVE-2021-30860, was fixed in iOS 14.8; Apple made further processing-path changes in iOS 14.8.1 and iOS 15.
- Google’s assessment concerned the sophistication of the analyzed iPhone exploit. It does not establish that all Pegasus operations used FORCEDENTRY, nor does it establish an equivalent Android exploit.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

