A California jury has awarded Meta more than $167 million in damages from Israeli surveillanceware slinger NSO Group, after the latter exploited a flaw in WhatsApp to allow its government customers to spy on supposedly secure communications. In May 2019 engineers at WhatsApp discovered a zero-click, zero-day vulnerability in the Meta-owned chat platform that would allow an attacker to install malware on a device with just a single phone call and no requirement on the victim to do anything other than have their handheld switched on. The surveillanceware in question was Pegasus, developed by the NSO Group. Pegasus is carefully designed to use zero-day vulnerabilities to infect handsets, ideally without any user interaction. Once on a phone, it has access to all and any data the devices contain, including phone records, emails, messages, and video, as well as the location of the device. It can even let its operator turn on the handset's camera and microphone for clandestine recording. Pegasus compromised around 1,400 WhatsApp accounts, and WhatsApp's engineers patched the flaw within days. But it's very unwise to f**k with billionaire Meta supremo Mark Zuckerberg; he unleashed the lawyers, who filed a lawsuit against NSO that October. On Tuesday, after less than two days of consideration, the eight-person jury handed out a fine that amounts to nearly three times NSO's annual R&D budget, according to Meta's estimates. In an extra twist of the knife, the company formerly known as ...
Super spyware maker NSO must pay Meta $168M in WhatsApp court battle
The Register
·Iain Thomson
·Published May 6, 2025
·Updated
Affected Software
2 affected components
Meta WhatsApp
Meta WhatsApp