iOS 16.6.1 fixes two vulnerabilities known to be actively exploited in the wild
support.apple.com
support.apple.com
> CVE-2023-41061: Apple
So if Apple discovered this bug, and Apple saw it exploited in the wild, the question needs to be asked... How did Apple find it in the wild? Was one of their own employees phished? Do they have monitoring on every phone to upload suspicious binaries running as root to the mothership?
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zer...
NSO group iPhone zero-click, zero-day exploit captured in the wild - https://news.ycombinator.com/item?id=37425007 - Sept 2023 (30 comments)
Heck this would probably need to be escalated to threaten the host country of the company with consequences if they're giving safe haven to a known bad actor.
https://www.nytimes.com/2023/04/02/us/politics/nso-contract-...
But - this doesn't prevent you once you have root to modify some app and system settings for the phone to reinfect itself eventually (proxies, vpn, who knows what)
Regardless, persistence is hard, which is why NSA and others recommend shutting off your phone at least once per week.