Murcielago for a Purism Librem 5 would be a good idea to protect against the threat you "surmised".
https://xcancel.com/GrapheneOS/status/1991139163203150065#m
Purism is using very low security components which are essentially end-of-life and never received proper security support. Purism also doesn't ship firmware updates for ideological reasons. They leave severe vulnerabilities unpatched. They blocked themselves doing it for some
user0 ipados is secure, but there always is BUT
It is not private
https://xcancel.com/GrapheneOS/status/1924510552287535506#m
Privacy involves much more including privacy from services, sandboxed applications, etc. macOS would win in many areas other than privacy from OS vendor [compared to Linux distros like Fedora]
A small amount of uninvasive telemetry isn't the catastrophe people make it out to be and LOTS of open source software including Firefox has similar telemetry to macOS. You aren't avoiding all telemetry, etc. by using open source software, and it's a tiny aspect of privacy
With this logic, iPadOS is even more secure and private than MacOS
DeletedUser237 nord and pia share the same owner whos a shady dud,
Nord has also failed to notify people of data breaches in a timely manner, and has downplayed those breaches
Hales Does grapheneos (which I like) have any third party testing
GrapheneOS also has been audited