There are also plenty of companies such as Lench/Gamma who overtly advertise their ability to penetrate any system. You can only buy or lease their software as a state actor, though.
there is a wide spectrum of actors in this space and besides the well known (Gamma/HackingTeam) also include many smaller firms that do not shy from working in a gray area and cater to both criminal enterprises, unstable regimes, warlords. Especially smaller fish fill the niche (AREA[¹], Negg[²], ...)
Though any of these providers they don't just give you a software because "solutions* would (due to their nature) rarely work out of the box. Instead they come with a consulting service contract to ensure the system is correctly used (to facilitate breaching the target). So "state actors" isn't restricted to spy-agencies but low-level law-enforcement who lack the budget and technical know-how for maintaining or creating these tools. So these systems are kind of a poor-mans TAO.
¹ https://www.linkedin.com/feed/update/urn:li:activity:6367357...
² https://twitter.com/ValbonneConsult/status/95357449457630412...
FFS.
Despite this, devs are still generally very cavalier about running code from the internet on their machines. Often times they have no choice of security mitigations because their package manager is compromised by flaws in its design.