The article claims that "a flaw in WhatsApp-owned servers" was used to "take over users’ phones". This seems to imply that the hackers were able to escape from the WhatsApp mobile app to perform other actions on the phones. How would this be possible? Or is this just likely careless journalism, and the exploit was that the server breach allowed the attackers to exfiltrate WhatsApp data only?
What WhatsApp & CitizenLab said to the victims in India about the attack[0].
[0]: https://scroll.in/latest/942218/nagpur-lawyer-notified-by-wh...