These fixes came out today, apparently timed with the announcement, make sure updates are applied for you and yours.
As far as I know, any parsing code for iMessages should run within the BlastDoor sandbox – is there another vulnerability in the chain that is not reported here?
For context, here's another report from them outlining a similar vulnerability: https://citizenlab.ca/2021/08/bahrain-hacks-activists-with-n...
But it is totally possible for them to have been able only to identify one of them if they didn't intercept the whole attack.
Looks like they just released an update that fixes CVE-2023-41064 at least: https://support.apple.com/en-au/HT213913