Also, I have to assume that every OS has security vulnerabilities that are not known to the public. If so, those can be used.
Also, I remember reading some story about something like Intel IPMI being used to read arbitrary memory remotely regardless of OS installed.
I think that there are far too many security holes for an agency with tons of employees and money to not be able to exploit. How many mathematicians and cryptographers does the NSA employ? I think that there is only one full time person working on GNU Privacy Guard.
I don't really see any information stored on a phone as safe. I would think that the manufacturer, the OS writer and the ISP can probably patch the phone, which can come with government spy ware.
I have no doubt that if if they want to target somebody that they can do it.
I think that is just a bunch of publicity to make the general public think that they are weak and impotent. Also, consider the fact that it has been reported that the government uses parallel construction to hide where the evidence really originated...