Cellebrite is a popular supplier for mobile forensics, which may require using vulnerabilities are not yet patched, i.e. finding or buying zerodays.
Edit: Oh, they ran up against this just a few weeks ago according to their Wikipedia article. How about that.
Google could potentially sue them under civil CFAA if there was some unauthorized access to Google infrastructure needed to develop the exploits, but that's unlikely to be the case.
Using NSO tools against unwilling targets would violate US law, but that's not what NSO does.
Standby while I look for a source.