RT @andrewcb
The NSO zero-click iMessage exploit is pretty mind-bending: it used a vuln in the JBIG2 image compression in PDF, and then, not having scripting, built a virtual CPU entirely out of boolean pixel operations.
All this just to hunt down some dissidents https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html