The RecordEndpoint / Device

WhatsApp v. NSO Group: a zero-click exploit compromised ~1,400 devices

NSO's Pegasus spyware infected around 1,400 WhatsApp users through a voice-call vulnerability — bypassing end-to-end encryption by taking over the phone itself.

01What actually happened

In May 2019, Meta detected that NSO Group's Pegasus spyware had targeted roughly 1,400 WhatsApp users — including journalists, activists, and diplomats — via a zero-click flaw in WhatsApp's voice-calling feature. WhatsApp sued NSO in October 2019; in May 2025 a California federal jury found NSO liable and ordered about $167 million in punitive damages. The exploit compromised the device endpoint, where messages are read after decryption, rather than breaking WhatsApp's encryption.

02Why it matters

End-to-end encryption is irrelevant once spyware owns the phone, because it reads everything post-decryption on the screen. No messenger — Cipher included — can stop spyware already running on a compromised device; this is precisely why E2EE is necessary but not sufficient.

Sources

We describe only what these sources report. If you think we've framed something inaccurately, tell us — accuracy is the whole point.

Cipher is built for exactly this gap: zero-access encryption, no phone number, on-device AI, and minimal metadata — so the failure in this story can't happen the same way.

See how the architecture works

Get on the list. Be early.

Join the waitlist and be among the first invited when Cipher opens.