Don't forget all the binary blobs you need to get full functionality, the monstrous size of the codebase (and corresponding attack surface), the baseband processor, etc.
Also, don't get me started on the terrible security hygeine of the actual ROM distribution practices.
Also, don't get me started on the terrible security hygeine of the actual ROM distribution practices.