Ok, so they can amortize expense and scarcity. But if they are reusing exploits, why isn't WhatsApp or the phone OS patched? I'm confused how they can be known functional infections, used multiple times, and then not get checked by the vendors? Even not be thwarted by some incidental app-patch. WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?
A lot of these exploits don't survive an update, power cycling, etc. Some, if they're done well, may also clean up after themselves.
Doing digital forensics on a restrictive mobile device (like an iphone or decent android phone) is difficult.
> WhatsApp and Signal must know of this, don't they have some AI tools to fuzz and fix?
Sure, but it's not a simple thing. That's why these exploits can go for millions. If it was easy to "fuzz and fix" these exploits would be worth nothing.