I suggest having a look to Youtube. Some fake iPhones are so good that unless you have a deep knowledge of the product, you can be fooled. I certainly would be fooled.
> As it is now these phones are not so easy to hack without user proactively installing malware and many of them would survive only until the next OS update or security response payload. A hardware attack is more compelling.
I'm confident those state actors have the payloads ready whenever they want to use it on high value targets, this is kind of naive. Pegasus NSO could be a public example of that.
You are not valuable enough to require such an exploit but that's a thing right now.