Apple has issued an emergency update closing three previously unknown iPhone vulnerabilities after researchers found that a single text-message link could silently jailbreak a device and install government-grade spyware capable of reading messages, recording calls and tracking a user’s movements.

The iOS 9.3.5 update released Thursday repairs an exploit chain researchers call “Trident.” Apple’s security bulletin identifies two kernel flaws and one WebKit vulnerability, each credited to Citizen Lab and mobile-security company Lookout. Together, the bugs could give an attacker control after a target taps a malicious link.

The attack was uncovered not through a routine laboratory search, but because Ahmed Mansoor, a human-rights defender in the United Arab Emirates, received suspicious text messages promising information about detainees allegedly tortured in UAE prisons. Instead of opening the links, he sent them to researchers.

The attack begins with a carefully crafted message aimed at a specific person. If the recipient follows the link, the browser is exploited, the operating system’s kernel protections are bypassed and spyware is installed without the ordinary approval process. The sequence turns three separate flaws into a reliable remote jailbreak.

Citizen Lab’s investigation of Mansoor’s messages connected the infrastructure to NSO Group, an Israeli company that sells a surveillance product called Pegasus to government customers. The report describes Mansoor as a repeated target of electronic surveillance because of his criticism of the UAE government.

Once installed, Pegasus can intercept calls and messages, collect contacts and calendars, monitor communications from encrypted applications, activate the microphone and camera, and report the device’s location. The spyware takes advantage of its privileged access inside the phone, gathering information after messages have been decrypted for the user.

A commercial market for zero-day access

The discovery offers a rare view of a private surveillance industry that buys or develops undisclosed software flaws and packages them for government use. These “zero-day” vulnerabilities are valuable precisely because the manufacturer and users do not know they exist. A working chain against a current iPhone can reportedly command a very high price.

Wired reported that Pegasus is marketed to state actors and can relay calls, emails, keystrokes, audio, video and other information to an operator. NSO Group says its technology is intended for governments fighting crime and terrorism, but the attempt against Mansoor demonstrates how such tools can be directed at civil-society figures.

Lookout’s technical guidance on Trident explains that the operation uses spoofed senders and anonymized domains to deliver the malicious link. It also warns organizations that a targeted executive or employee could expose corporate information if a compromised personal device connects to work services.

Apple moves quickly after disclosure

Citizen Lab and Lookout notified Apple on August 15. Ten days later, the company distributed iOS 9.3.5 to compatible iPhones, iPads and iPod Touch devices. The short interval illustrates the seriousness of the flaws and the advantage of responsible disclosure, but it also means users must install the update before the fix protects them.

Apple’s bulletin says one flaw could disclose kernel memory, another could execute arbitrary code with kernel privileges and the WebKit bug could allow code execution through malicious web content. Ars Technica’s analysis notes that all three were being exploited before patches were available, making the release an urgent security update rather than a routine maintenance package.

The vast majority of iPhone owners are unlikely to be selected for a costly, individualized Pegasus operation. But the existence of the exploit affects everyone running vulnerable software. Once knowledge of a flaw spreads, other attackers may attempt to reproduce it, and a tool built for a narrow intelligence target can eventually be adapted or leaked.

The security boundary moves inside the phone

Pegasus is especially consequential because it does not need to defeat encryption in transit. Applications such as iMessage, WhatsApp and other secure messengers may protect data between endpoints, but spyware controlling an endpoint can read messages on the screen, capture keystrokes or record audio directly.

Network World reported that the attack can steal a broad range of information and had been associated with targets beyond Mansoor, including an investigative journalist. The incident therefore shifts debate from theoretical access to demonstrated compromise of fully updated consumer devices.

It also strengthens Apple’s argument that deliberate “back doors” for law enforcement would add risk to systems already facing sophisticated efforts to gain entry. The Federal Bureau of Investigation’s dispute with Apple over the San Bernardino gunman’s phone focused on compelled assistance; Pegasus shows a commercial market pursuing access without the manufacturer’s cooperation.

Updating is the immediate defense

Users should install iOS 9.3.5 through Settings, General and Software Update. The patch is available for the iPhone 4s and later, iPad 2 and later, and fifth-generation iPod Touch and later. Devices that cannot receive current security updates remain more exposed as exploit techniques evolve.

BleepingComputer’s technical report advises prompt installation and describes the chain as a remote jailbreak used to place Pegasus on a target device. Users should also treat unexpected links—especially those carrying urgent or emotionally tailored claims—with suspicion.

The most important lesson is not that iPhones are uniquely insecure. It is that a widely trusted platform attracted a sophisticated, well-funded attack capable of combining several rare vulnerabilities. Apple has closed the specific doors identified by researchers, but the commercial incentives to find others remain.

Mansoor’s refusal to tap a link prevented an invisible compromise and exposed a surveillance capability that might otherwise have remained secret. For hundreds of millions of iOS users, that individual act created a patch. For governments, security companies and technology manufacturers, it revealed how quickly the boundary between targeted espionage and consumer risk can collapse once a zero-day weapon is found in the wild.