A zero-click attack is a type of cyberattack that doesn’t require the victim to take any action, such as clicking a link or opening an attachment. Instead, attackers exploit vulnerabilities in software to inject malicious code, often hidden in seemingly harmless data, which then automatically infects the device.