I think OP is asking how NSO was able to escape the phone's sandbox model. To do that, they would need an exploit for the phone's OS,
in addition to the WhatsApp exploit. So, the obvious question: which operating systems were specifically targeted?
Another comment mentions Pegasus... that was an iOS exploit patched in 9.3.5 (3 years ago). Does that line up with the timeline of this article?
Given that Android exploits are far more common than iOS, I would expect they had one of those too.
But then, where are Apple and Google in this case? It wasn't solely Facebook who was exploited; their app was just the initial vector to escalate to an attack on the OS. NSO probably could have achieved the same with dozens of other apps, but WhatsApp was chosen because of ease of deliverability (messaging) and popularity.