WhatsApp v. NSO Group: a zero-click exploit compromised ~1,400 devices
NSO's Pegasus spyware infected around 1,400 WhatsApp users through a voice-call vulnerability — bypassing end-to-end encryption by taking over the phone itself.
01What actually happened
In May 2019, Meta detected that NSO Group's Pegasus spyware had targeted roughly 1,400 WhatsApp users — including journalists, activists, and diplomats — via a zero-click flaw in WhatsApp's voice-calling feature. WhatsApp sued NSO in October 2019; in May 2025 a California federal jury found NSO liable and ordered about $167 million in punitive damages. The exploit compromised the device endpoint, where messages are read after decryption, rather than breaking WhatsApp's encryption.
02Why it matters
End-to-end encryption is irrelevant once spyware owns the phone, because it reads everything post-decryption on the screen. No messenger — Cipher included — can stop spyware already running on a compromised device; this is precisely why E2EE is necessary but not sufficient.
Sources
- The Record · May 20251,400 Pegasus spyware infections detailed in WhatsApp's lawsuit filings
- Washington Post · May 2025Spyware-maker NSO ordered to pay $167 million for hacking WhatsApp
We describe only what these sources report. If you think we've framed something inaccurately, tell us — accuracy is the whole point.
Cipher is built for exactly this gap: zero-access encryption, no phone number, on-device AI, and minimal metadata — so the failure in this story can't happen the same way.
See how the architecture works