There really isn't something new here other than a fancy name - or I am not seeing the point.
There really isn't something new here other than a fancy name - or I am not seeing the point.
A zero click remote code execution, would be for example where the attacker send a message, and their phone just processing the message on it's own is enough for the attacker to execute code on the victims device.
A non zero click vulnerability can be mitigated by being cautious. A zero click vulnerability cannot.
You get owned without clicking hence zero click. Is it different from RCE? A subset? Doesn't matter. Title could have said RCE.
No amount of caution will save you when the exploit is injected into a major website.
Why bother with such meaningless distinction? Does your browser never hit any http:// resources?
I think this just goes to show how silly this new terminology is.