WhatsApp says flaw let attackers install NSO Group surveillance software on iPhones and Android phones since May via the app's call function; flaw now patched
A vulnerability in the messaging app WhatsApp has allowed attackers to inject commercial Israeli spyware on to phones, the company and a spyware technology dealer said.
Context & Ripple Effects
This May 2019 disclosure is the origin point of WhatsApp's multi-year confrontation with NSO Group. The call-function exploit let the Israeli vendor's spyware land on iPhones and Android phones without user interaction, and the company's investigation of it fed directly into the lawsuit against NSO Group filed that October over the attack on roughly 1,400 devices.
The targeting was not abstract: by November, WhatsApp had told Indian authorities that 121 users in India were hit, including activists, journalists, and civil rights lawyers. The pattern has since repeated — a zero-click iOS and Mac bug fixed in 2025 shows the same attack surface being worked years later.
First-order effects
- WhatsApp users on both iPhone and Android had to update immediately, since any incoming call could carry the payload — no click or answer required; the patch is the only mitigation for devices already exposed since May.
- NSO Group loses its flagship delivery vector overnight, forcing its government customers back to costlier or less reliable intrusion methods.
Second-order effects
- Apple and Google face pressure to harden their platforms against messaging-app exploits, since the flaw sat in WhatsApp's call handling but ran on their operating systems.
- Human rights groups and journalists — the documented targets in India — gain evidence for litigation and export-control campaigns against commercial spyware vendors like NSO Group.
Third-order effects
- If the pattern holds, zero-click exploits delivered through mainstream apps become the standard tool of state-adjacent surveillance, pushing platform makers toward architectural defenses (sandboxing, memory-safety rewrites) rather than per-bug patching.
- Commercial spyware becomes a regulated industry question: recurring disclosures like this one build the case for export licenses and legal liability for vendors selling intrusion tools to governments.
The trend: Consumer messaging apps are becoming the primary battleground between platform security teams and commercial surveillance vendors, with each patched zero-click exposing more of the spyware supply chain.