One way to resolve the tension here is to note that CNE and lawful-intercept access to phones depends generally on platform vulnerabilities, not application code vulnerabilities. Low-level platform code churns less, absorbs more fixes under AI workloads than it does new features, and works in a constrained space where guardrails are easier to provide (and where those guardrails already have institutional support at Apple and Google).
Over the long term this state of play could change, and IC/LEO organizations could start leaning more on application vulnerabilities than on platform RCEs. But the action would probably still coalesce around a couple of app-layer targets that could themselves be hardened.
Lawful-intercept is in general implemented at the server equipment of telecom operator, not in the phones. In general, intelligence services don't access phones, if the interception can be done at the operator, because this could alert the subject or expose their techniques.
According to a friend, who is working for an telecom company in Europe, Lawful-intercept is done at a server rack provided by and managed by a law enforcement agency, all traffic of this telecom company is copied to this server rack. The server rack also has a second direct connection to the law enforcement agency. Employees of the telecom company don't know which phone numbers are targeted or which traffic is intercepted.
Over the long term this state of play could change, and IC/LEO organizations could start leaning more on application vulnerabilities than on platform RCEs. But the action would probably still coalesce around a couple of app-layer targets that could themselves be hardened.