If everyone is using message service X, then we'll start seeing more attacks on X.
The exploits we've seen over the last few years haven't been in iMessage the app, they've been in a host of different things. The most recent security brouhaha was apparently in the webp library[1] that also effected chrome, webkit, Firefox, every electron app, and I assume every app on android, iOS, macOS, that uses system image decoders, etc. But if you want a specific target then you aren't going to use something like a random webpage or phishing email if you have something that you can guarantee will go to only one device that you know is exploitable, and you can guarantee how it will be handled - i.e. the builtin system messaging apps.
[1] and even here the attack didn't happen from iMessage
I'm actually now curious whether the various awful web notification standards allow images?
As I recall, the disclosures of major vulnerabilities in iMessage don't say that regular SMS messaging is effected.
But also, in answer to the question: yes, every messaging app on Mac or iOS that could display webp was susceptible to this exploit. If they use ImageIO then the OS update fixes them, if they use their own copy of libwebp they are exploitable until they ship an updated version.
(But I can't find a source for this atm. I remember reading it somewhere, but maybe I'm confusing it with a previous Blastdoor exploit.)
It was triggered because the system shows a preview of the image by default.
Devices that had Lockdown Mode enabled no longer show preview images, so were not effected.
>Lockdown Mode is an extreme protection feature for iPhone. Its protections include safer wireless connectivity defaults, media handling, media sharing defaults, sandboxing, and network security optimizations.
https://support.apple.com/guide/iphone/use-lockdown-mode-iph...
> On September 7, 2023, Apple released emergency security updates to fix a buffer overflow vulnerability (CVE-2023-41064) impacting macOS, iOS, iPadOS, and watchOS products that was used in a zero-click exploitation chain by the NSO Group. Shortly after, on September 11, 2023, Google released an update to fix a buffer overflow vulnerability (CVE-2023-4863) in Google Chrome, which was reported by Apple’s Security Engineering and Architecture (SEAR) and Citizen Lab. Both vulnerabilities were nearly identical and listed as actively exploited, leading to confusion across the security community.
Note: Citizen Lab urges all at-risk users to enable Lockdown mode as this has been confirmed by Apple’s Security Engineering and Architecture team that Lockdown Mode blocks this particular attack.