Citizen Lab, working with the SHARE Foundation, reports that an iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware. The analysis concludes that the compromise occurs through an iMessage “zero-click” exploit, meaning the target does not need to interact with a link or attachment. Citizen Lab says it identifies “high-confidence indicators” of Pegasus activity on the device.

The two reports describe the same core finding: infection via an iMessage zero-click vulnerability used to deploy Pegasus. While neither outlet in the provided text details broader impact, technical steps, or attribution beyond the spyware vendor, the shared framing focuses on the method of infection and the presence of Pegasus indicators identified by Citizen Lab. Both accounts also treat the incident as part of wider concerns about spyware deployed through mobile messaging systems.

Overall, the sources align on who was targeted (a Serbian student movement member), the tool involved (Pegasus), and the delivery mechanism (iMessage zero-click exploitation), while offering limited additional specifics about timeline, scope, or investigative next steps in the excerpts.