Does IOS count? In that case people have been compromised without clicking anything and just getting an invisible text message is enough. Browsers have exploits with sandbox escapes. Any link to a file that is automatically downloaded and opened in an application (office doc or PDF for example) can exploit vulnerabilities in the underlying application and allow for anything including remote code execution.
autoexec|1 year ago
mrguyorama|1 year ago