Definitely not an expert but I'm presuming they take advantage of the "helpful" behaviour those apps have to preview content and then pair that with some sort of exploit in the library that parses/displays the content. So say they have an exploit in a jpeg library that whatsapp uses then they send a specially-crafted jpeg via whatsapp, whatsapp "previews" the image and that triggers the exploit to compromise the jpeg library and pwn the user.
[1] https://www.ft.com/content/4da1117e-756c-11e9-be7d-6d846537a...
[2] https://appleinsider.com/articles/23/06/01/zero-click-ios-ma...
Also these attacks are aimed at individuals and executed by state actors. They likely already knew what phone, OS, and browser the MEP was using and selected an appropriate attack from the catalog.
This has been the reality of mobile phone security for almost a decade now. Any sufficiently-complex digital system will be rife with UB and exploits.
They might also have specific software installed across most of them that could be part of the targeting.