But it correctly supports HTTPS right? If so, then a MITM attack shouldn't be possible unless your system trusts a bad CA.
iPhones are a bit more restrictive apps can install their own CA/trusted certificates but these are accessible to the only the apps iirc Apple manages the general trust store on its own with system update.
The only effective way to get guaranteed security is with HSTS preloading. Anything short of that leaves you vulnerable to the linked attack, which dates way back to 2012.
It was far more relevant when websites were mostly HTTP, but used HTTPS for login or payment pages.
The only way to get guaranteed security is if your browser will only ever make HTTPS connections to a given domain name, and that requires HSTS preloading.