Zero-click attack
An attack that needs no action from the victim at all, not even a click.
Most security advice assumes you have to do something wrong: click a dodgy link, open an attachment, install something you should not have. A zero-click attack skips all of that. The malicious data arrives through a channel your software already listens on, such as a message, an image or a video call, and the program processes it automatically. Being reachable is enough.
That is what makes this class so serious. There is no user mistake to blame and usually no visible sign that anything happened. The August 2026 Zoom flaws were a textbook example: simply being in a meeting was enough for another participant to take over your device. The defence is not vigilance but plumbing, mainly patching quickly and switching off features you do not use, since every extra feature is another piece of code that reads data from strangers.