It should be explained to public how such exploit take place, with open sourcing necessary parts. Otherwise there is no way for us to know it wasn't intentional at first place.
I am not meaning there is a possibility like Apple as a company decides to put exploits. However governments can easily do it with single engineer at right place.