Yeah I thought it was widely known that "deploy" could be as simple as sending a text message. The recipient did not even need to open in in the case of Pegasus.
So you're presuming that there is an exploit that allows a remote attacker to install "Graphite" via a text message? That is not stated here - or anywhere - as it was over and over again in the case of Pegasus (and similarly, the trumpets sounded when the patch was fixed a couple weeks later).
The reporting here is markedly more imprecise, and it's frustrating.