What doesn't add up is that, in the real world, you can't protect against every threat model. Its their job to protect the best they can. They can't tell Apple to stop building their phones in China, but they can simply say "Don't buy Huawei".
That's easy. And moreover, its a bigger threat. With a Huawei phone, the Chinese government has control over everything from the processor to the userspace software. With a small piece of silicon in a fab, the threat surface is much smaller; they'd have to sneak it in against Apple's will, past all of Apple's American-loyal QA.
In the software world, we tend to think about security as an absolute, because computer logic is absolute. In the real world, security is probabilities. How can you minimize the chance of breach while minimizing costs.