Basically the distinction is one of law enforcement authority, not legality.
Even in USA that likely could be legal with an appropriate court warrant, and many other countries have more permissive constitutions.
Can you expand upon this? I'm not particularly familiar but it doesn't seem right. Obviously LEO agencies are allowed to subpoena private information, but can they legally use exploits with a warrant? Are there recorded examples of this?
[Based on your reference to warrants, I guess I'm excluding the NSA or other supposed state-level spy agencies that supposedly secretively deploy such tactics]
It's well established that with an appropriate warrant, LEO have always been able to come into your house without telling you and add hidden surveillance bugs to listen on your communications; they have always been allowed to physically modify or replace your phone (e.g. physical phone wiretaps a century ago); Electronic Communications Privacy Act reasserts that this applies also to electronic surveillance and digital communications; so (as a non-expert) I don't really see why that wouldn't apply to smartphone exploits as well. We do see exploits being applied to devices in LEO possession (e.g. https://www.theverge.com/2021/4/14/22383957/fbi-san-bernadin... for one random example) to recover evidence.
The main restriction is the constitutional limits of 4th amendment which requires specific warrants for each case - which is a significant practical obstacle, so the circumstances in which warrantless wiretapping is permitted (e.g. by PATRIOT act) is a contentious issue; however, it's not relevant if a proper warrant is obtained.
> As part of this effort, the End-User Review Committee of the BIS decided to add four foreign entities, among them two Israeli companies, NSO Group and Candiru, to the Entity List. The U.S. Export Administration Regulations (‘EAR’) impose additional license requirements for exports to listed entities, and limits the exceptions for exports, reexports, and transfers to such entities.
But they continue:
> The existing international and national frameworks regulating the export of sensitive spyware technologies lack the teeth necessary to deal with contemporary issues relating to the abuse of these technologies and the growing need for their enhanced supervision.
[0]: https://www.law.georgetown.edu/ctbl/blog/managing-risky-busi...