Google's Threat Analysis Group discovered a 0-day exploit chain used by a commercial surveillance vendor in Egypt to install spyware on iPhones. The exploit chain was delivered via a man-in-the-middle attack and included three vulnerabilities that were patched by Apple in iOS 16.7 and iOS 17.0.1. The vendor also had an exploit chain for Android devices. The discovery highlights the risks of commercial surveillance and the importance of prompt patching.