Trident Spyware Explained: How Pegasus Reached iPhones in 2016 and How Zero-Click Attacks Work Now

Discover how the Trident spyware exploit compromises iPhones using zero-click vulnerabilities. Learn about Pegasus, how the attack works, who's at risk, and how to protect your device.

May 26, 2025 - 12:44
Updated: 8 days ago
113.4k
Trident Spyware Explained: How Pegasus Reached iPhones in 2016 and How Zero-Click Attacks Work Now

Quick answer: Trident was a chain of three iOS zero-day flaws (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657) used in 2016 to install NSO Group Pegasus spyware after a user tapped a link. Apple fixed them in iOS 9.3.5. Trident needed one tap, so it was not truly zero-click; later Pegasus attacks such as FORCEDENTRY needed no interaction.

Key takeaways

  • Trident used three flaws: a WebKit bug for code execution, a kernel information leak and a kernel memory corruption flaw.
  • It was reported in August 2016 by Citizen Lab and Lookout and fixed in iOS 9.3.5.
  • Trident needed the victim to open a link, so it was a one-click attack. Zero-click attacks like FORCEDENTRY came later.
  • Keep iOS updated, restart regularly and consider Lockdown Mode if you are at high risk.
  • If you suspect targeting, contact a digital security helpline or CERT-In rather than relying on a scanning app.

What was Trident spyware?

Trident is the name given to a chain of three previously unknown iOS vulnerabilities. In August 2016, researchers at Citizen Lab and Lookout analysed a link sent by text message to a human rights activist. The link led to a page that exploited the chain and installed Pegasus, a commercial surveillance product made by NSO Group. Apple released iOS 9.3.5 to fix the flaws.

How did the Trident exploit chain work?

The three flaws were used in sequence. The earlier version of this page listed them in a different order and called the attack zero-click, so we corrected both.

OrderCVEFlawRole
1CVE-2016-4657Memory corruption in WebKit (Safari)Code execution when the link is opened
2CVE-2016-4655Kernel information leakReveals memory layout to defeat protection
3CVE-2016-4656Kernel memory corruptionRuns code in the kernel and removes restrictions

Check each entry on the National Vulnerability Database for the official description and Apple advisory references. The step to remember: a browser bug gets code running, then two kernel bugs break out of the sandbox.

Was Trident a zero-click attack?

No. The victim had to tap a link, so it was a one-click attack. A zero-click attack needs no action. The best-known later example is FORCEDENTRY (CVE-2021-30860), found by Citizen Lab in 2021 and delivered through iMessage processing. Apple has since added protections such as BlastDoor for message parsing and an optional Lockdown Mode, introduced with iOS 16. Check Apple documentation for the current feature set.

What can Pegasus do after infection?

Public analyses describe access to messages, calls, contacts, location and, with permissions it gains, the microphone and camera, as well as data from messaging apps. Capabilities vary by version. Rely on Citizen Lab and vendor reports rather than marketing claims. For a broader view of the threat type, read what spyware attacks are and how to prevent them, common malware types and a related surveillance tool, China Massistant.

Who is targeted?

Reports link Pegasus to attacks on journalists, activists, lawyers and officials. Most people are not likely targets, but the defences below cost little and help everyone.

How do you protect your iPhone?

  1. Install iOS updates promptly. Trident was fixed within days of discovery. Unpatched devices are the main risk.
  2. Do not open unexpected links, even from known contacts, if the message looks odd.
  3. Restart the phone regularly. It can disrupt some non-persistent implants.
  4. Use Lockdown Mode if you are at higher risk. It limits features that attackers use.
  5. Use a strong passcode and turn on Apple ID two-factor authentication.
  6. Do not jailbreak a phone you depend on.

How can you check for compromise?

Consumer scanning apps have limits, because iOS does not let apps inspect other apps. Forensic checks use a backup or device logs. Amnesty International has published an open-source tool called MVT, Mobile Verification Toolkit, which checks backups against known indicators (see the project on GitHub). A clean result does not prove safety, because the indicators list covers only known cases. If you think you are a target, contact a digital security helpline, and report to CERT-In where it is a crime.

Can similar spyware hit Android?

Yes. Commercial spyware has been reported on Android as well. The advice is the same: update the system and apps, avoid unknown links, and use built-in protections.

Next steps

Next steps: to learn defence in depth, see our Cyber Security course, and read what spyware attacks are and how to prevent them.

Frequently Asked Questions

Trident is the name for a three-flaw iOS exploit chain (CVE-2016-4655, CVE-2016-4656 and CVE-2016-4657) used in 2016 to install NSO Group Pegasus spyware after a victim opened a link. Apple patched it in iOS 9.3.5.

A link opens in Safari and exploits a WebKit flaw to run code. A kernel information leak then reveals memory layout, and a kernel memory corruption flaw gives control of the device. Pegasus is installed afterwards.

Pegasus is commercial surveillance software made by NSO Group. Once installed, public analyses say it can read messages, track location and switch on the microphone or camera. Capabilities vary by version and platform.

Citizen Lab at the University of Toronto and the mobile security firm Lookout analysed the attack in August 2016 after a human rights activist received a suspicious text message with a link, and reported it to Apple.

The specific flaws were fixed in iOS 9.3.5, so up-to-date devices are not affected by them. The wider risk remains, because later exploit chains, including zero-click ones, have been used. Keep iOS updated.

Yes. Commercial spyware has been reported on Android devices as well. Trident itself targeted iOS, but the defences are alike: patch quickly, avoid unknown links and apps, and use built-in security features.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.