In addition to the fact that they're not a US company, selling exploits doesn't actually violate CFAA.
Google could potentially sue them under civil CFAA if there was some unauthorized access to Google infrastructure needed to develop the exploits, but that's unlikely to be the case.
Using NSO tools against unwilling targets would violate US law, but that's not what NSO does.