I won't expect US devices not to have government backdoors in one way or another. Sure they can talk a lot about secure elements and so on. The actual backdoor is then placed somewhere else and doesn't need to crack that.
If a device is in regular use (no before first unlock state), I for example expect that both Apple and Google are willing to push a special update to the device. Both stores are capable of installing apps without user interaction on the device and any limitations why this usually needs user confirmation when triggered via web can be bypassed by the companies. Both stores run with elevated privileges and can probably push more changes than just installing and updating apps (which still would run in a sandbox).
I would not even fully trust the hardware. It is way harder to find backdoors in there. Again they probably rather target the firmware of the modem or something like this and not the secure element. Every security researcher focuses on if the security features are watertight, so you place something that can access data once the secure element is unlocked somewhere where nobody is looking for it.
That's also why Graykey has less options (they leaked slides some time ago) in the before first unlock state: If the encrypted partition is not mounted (or the FS based encryption not unlocked) you need to target the secure components instead of having some trojan software exfilterating the unlocked data.