LiMP VPN

Zero-Click Attacks: How Phones Get Hacked Without a Tap

Zero-Click Attacks: How Phones Get Hacked Without a Tap

Short version: a zero-click attack infects a phone with no action from the victim at all — malicious code runs during the automatic processing of an incoming message, audio file, or sync event. For the average person this threat is rare: it's an expensive tool used in targeted operations against journalists, activists, diplomats, and executives. But exploits eventually leak and get cheaper, so fast updates and a smaller attack surface still matter for everyone. A VPN covers the network side of this picture — interception, DNS spoofing, malicious domains — but it can't see an exploit that arrives inside an already-encrypted messaging app.

Below is a plain-language breakdown: how the exploit chain actually works, which delivery channels exist, who is realistically a target, and which Android and Windows settings actually shrink the risk. If you've already read up on what a VPN protects against — and what it doesn't, this fills one specific blind spot: a class of attacks a VPN simply cannot see.

What a zero-click attack actually is

Ordinary phishing needs an action: clicking a link, opening an attachment, typing a password into a fake page. A zero-click attack skips that step entirely — the victim doesn't tap anything. The phone itself automatically parses whatever arrives: it renders a message preview, generates an image thumbnail, transcribes a voice note into text, or syncs data between linked devices. All of that happens in the background, with no user involvement, and that background processing is exactly where the attack gets in.

What makes this possible is the sheer complexity of modern media formats. The code that decodes audio, images, or attachments runs with system or app-level privileges before the content is ever shown to the user. If that decoder contains a zero-day vulnerability — a bug the vendor doesn't know about yet — a specially crafted file turns ordinary parsing into arbitrary code execution.

The difference from "one-click" attacks is fundamental: one-click tricks a person, zero-click has no one to trick. No human makes a decision, so the security-awareness training that helps against phishing is powerless here. The only real lever is keeping vulnerable code from ever receiving that input in the first place, and patching the underlying bugs as fast as possible.

How the attack works: from a single message to full device control

A typical zero-click chain has several stages. First, the attacker delivers a specially crafted file — a message in a chat app, an MMS, an audio attachment, sometimes just a packet over nearby Wi-Fi or Bluetooth. A built-in parser then tries to process that file — and hits a bug. The first exploit usually runs inside the app's own sandbox, so the attacker needs a second step: escaping the sandbox or exploiting a separate kernel bug to reach the file system, camera, microphone, and messages. After that, an implant — a spyware module — gets planted on the device, collecting data and sending it to the attacker's server.

Chaining several independent vulnerabilities like this is expensive, which is why these tools stay pricey and get used narrowly rather than at scale. But each example below shows that "I never opened anything" is not a safety guarantee against zero-click.

2026 example: an audio message on the Pixel 9

In January 2026, Google's Project Zero researchers described a working exploit chain against the Pixel 9. On some devices, Google Messages automatically processes incoming SMS/RCS messages with audio attachments — including background auto-transcription of voice into text, even if the user never opened or played the recording. A bug in the Dolby decoder, tracked as CVE-2025-54957, allowed code execution in the app's context while parsing such an audio file; a second flaw in a kernel driver, CVE-2025-36934, provided the sandbox escape needed for full device control. Google shipped patches for both in early January 2026.

Example: iMessage and Pegasus

The best-known class of zero-click attacks involves Pegasus spyware from NSO Group and similar commercial mercenary-spyware tools. In 2021, the ForcedEntry chain exploited an image-processing bug in iMessage with no action required from the recipient. The pattern repeated in 2026: according to Citizen Lab and Serbia's SHARE Foundation, at least 14 people connected to a student protest movement in Serbia were infected with Pegasus through a zero-click iMessage exploit; the flaw was fixed in iOS 18.4.1.

Example: WhatsApp and an image

In 2025, researchers found and closed a two-vulnerability chain: CVE-2025-55177 in WhatsApp's linked-device synchronization and CVE-2025-43300 in Apple's ImageIO image-processing component. Together, they let an attacker compromise a device with a specially crafted image and zero action from the recipient. Apple patched its side on August 20, 2025, WhatsApp patched in late July/August the same year, and CISA added the pair to its Known Exploited Vulnerabilities catalog.

Which channels zero-click attacks actually travel through

Each delivery channel has its own mechanics — and its own defense. A VPN helps with some of these and does nothing for others. Here's the full picture.

ChannelExample vectorWhat lowers the riskDoes a VPN help
Messaging apps (iMessage, WhatsApp)attachment, device syncapp and OS updates, disabling media auto-downloadNo — traffic runs inside the app's own encrypted channel
SMS / MMS / RCSaudio or MMS attachment, auto-transcriptionupdates, disabling auto-processing and auto-download of attachmentsNo
Nearby Wi-Fi / rogue access pointattack on the Wi-Fi stack, session hijackingdisable auto-connect to open networksPartially — encrypts content, but doesn't fix a bug in the driver itself
Bluetoothattack on the Bluetooth stack within rangeturn it off when not in useNo
Cellular network (2G, rogue base station)baseband attack, SMS blasterblock 2G connections (Android 12+), Android Advanced ProtectionNo at the radio level; data traffic over the connection — yes
Network traffic (plain HTTP, DNS)response spoofing, redirect to an exploit siteHTTPS, encrypted DNS (DoH/DoT)Yes — the tunnel and DNS queries run inside the VPN

Attacks via rogue access points and nearby cellular equipment aren't theoretical — the mechanics are covered in our deep dives on fake Wi-Fi networks (evil twin attacks) and SMS blasters using a fake cell tower. Both scenarios require the attacker to be physically near the target, which is why they're used for targeted surveillance far more often than for mass attacks.

Who is actually at risk from zero-click attacks

A full chain of several zero-day vulnerabilities is expensive to build and stays usable only until the vendor patches it. That economics forces narrow, targeted use: against journalists investigating corruption or organized crime, human rights activists, politicians and diplomats, and executives with access to sensitive data. The average person isn't facing Pegasus — they're facing far cheaper schemes, like fake banking apps that talk a user into installing them manually and granting permissions. That's a fundamentally different attack type: there, the victim takes an action; here, they don't.

There's a middle scenario worth knowing about, too. Once a vendor patches a flaw and a public write-up appears (like the examples above), less sophisticated groups start reproducing simplified versions of the exploit against devices that haven't installed the patch yet. So anyone who delays an update for weeks effectively becomes a "second-wave" target — not for the expensive targeted tool, but for its cheap copycat. More on why slow patching is risky in our piece on smartphones without security updates.

How to protect Android from click-free attacks

You can't eliminate zero-click risk entirely — no vendor guarantees zero zero-days. But you can systematically shrink the attack surface: the less code is automatically parsing incoming data without your involvement, the fewer entry points an attacker has.

The single biggest lever is patch speed. Turn on automatic updates for the OS, for Google Play System Update (the channel Google uses to ship some security fixes between major Android releases), and for apps — messaging apps especially. Where it's supported, turn on Android Advanced Protection, a mode that tightens a whole set of system settings at once, including blocking connections to the older, less secure 2G network.

  • enable automatic updates for the OS, Google Play System Update, and apps;
  • turn on Android Advanced Protection and 2G blocking wherever your device supports it;
  • disable auto-download of media and voice messages in WhatsApp, Telegram, and similar apps — at least for unknown contacts;
  • keep Bluetooth and NFC off when you're not actively using them;
  • disable auto-connect to open and previously saved Wi-Fi networks;
  • remove messaging apps and software you don't actually use — each one is another parser for incoming data.

On Windows, the principle is the same, just in different components: keep the OS and browser on automatic updates, avoid opening previews of attachments from unverified emails or file-sharing links, and don't disable built-in Microsoft Defender without a good reason — it also covers part of the automatic-file-processing attack surface.

Where a VPN helps — and where it doesn't

A VPN encrypts all traffic between your device and its server and hides it from your ISP, a public Wi-Fi operator, or the owner of a rogue access point. That closes a specific class of threats: intercepting unencrypted traffic, DNS response spoofing, and redirects to malicious domains — including some of the domains used to deliver network-based exploits. Some VPN services additionally block known malicious domains at the DNS level; that's an extra layer, not a substitute for patching.

Being honest about the limits: a VPN cannot see or block an exploit that arrives inside a messaging app's own encrypted channel, over Bluetooth, or through an attack on the phone's radio modem — your traffic never touches those mechanisms before it reaches the VPN tunnel. Think of a VPN as one layer of defense, not the only one. LiMP VPN for Android encrypts all outbound device traffic under a no-logs policy — a solid baseline layer for any network you don't trust, on top of the updates and settings above, not instead of them.

Got a threat notification? Here's what to do

On August 13, 2026, Apple sent out a wave of Threat Notifications — alerts about attempted mercenary spyware attacks — to users in 110 countries. The notification now appears not just by email and on the Apple Account page but directly on the lock screen. Apple is explicit that a genuine notification never contains a link to click, never asks you to install a configuration profile, and never asks for a verification code — all of those are signs of a fraudulent imitation. The only reliable way to verify authenticity is to type account.apple.com into your browser manually and check your account there, never through a link from the message itself.

If you received such a notification or suspect infection: don't rush to wipe the device — that destroys the evidence investigators need to analyze what happened. It's better to reach out to a dedicated digital-security resource, such as the Access Now Digital Security Helpline or Amnesty International's Security Lab, which handle exactly these cases. A reboot is a reasonable temporary step: many spyware implants don't survive a restart and lose their foothold, although the underlying vulnerability that let them in isn't fixed by a reboot alone, and re-infection remains possible. For genuinely sensitive conversations, consider switching temporarily to a separate, less conspicuous device. If you're noticing unusual phone behavior without an official notification, start with our guide on signs your phone is hacked.

Checklist: cutting zero-click risk today

  • turn on automatic updates for your OS and every app, especially messaging apps;
  • install security patches the day they ship — don't put it off;
  • reboot your phone every few days — it breaks many non-persistent implants' active session;
  • keep Bluetooth and NFC off when you don't need them right now;
  • block 2G connections in settings if your device supports it;
  • limit auto-download of media and voice messages in messaging apps;
  • remove messaging apps and software you no longer actually use;
  • on unfamiliar or public networks, connect only through a VPN.

Frequently asked questions

Can you get infected by a zero-click exploit just from an incoming call?

Yes — in 2019 an attack spread through WhatsApp that triggered from the act of receiving a VoIP call alone, with no need to answer. That specific flaw is patched now, but the principle holds: even an incoming call can be an attack vector.

Do I need separate antivirus software to guard against zero-click on Android?

Antivirus doesn't replace updates: most mobile antivirus tools run inside the app's own sandbox and can't see kernel-level exploits. Their job is catching fake apps and known malicious APKs, not zero-day attacks.

How fast do I actually need to install security patches for this to matter?

The same day they ship, whenever that's practical — once a fix is published, the risk for unpatched devices rises because exploit details become known to attackers too.

Is zero-click risk different on home Wi-Fi versus a cafe network?

Yes: at home you control the router and its settings, in a cafe you don't. A public network adds the risk of a rogue access point and traffic interception, which is exactly where a VPN and disabled auto-connect matter most.

Can unusual data usage or battery drain tell me my phone has an implant?

Sometimes indirectly, but it's an unreliable signal — modern implants are built to minimize that kind of footprint. More reliable signs are covered in our guide on recognizing a hacked phone.

Should I disable RCS and go back to plain SMS for safety?

That's not necessary: the risk comes from automatic attachment processing, not the protocol itself. It's more effective to disable media auto-download and auto-transcription in your messaging settings while keeping RCS on.

Read also

Use Cases

VPN Anonymity Check: 2026 Checklist

12 min read
Use Cases

SMS Blasters: How Fake Cell Towers Send Scam Texts

10 min read
Use Cases

Discord Not Working With VPN: Causes & Fixes 2026

11 min read

Secure your connection in a minute

Download LiMP VPN for free and feel the difference within a minute.

Download for AndroidPricing