The Project Pegasus

Latest ios is vulnerable to this malware.

They mention a zero click solution. Does that mean simply receiving those iMessages itself would open up the phone or the user had to click those links?
From what I read, link click. There was also mention of loading a malicious image.
