Earlier quoted context omitted.
Sending the malware via iMessage, assuming the flaw was part of iMessage and not standard SMS.
But if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.
From the complaint:
>Count One
>Violations of Computer Fraud and Abuse Act
https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11...
The EULA is used to establish jurisdiction, and for the separate breach of contract claim. Apple has servers around the world, without the EULA the jurisdiction isn't necessarily obvious.