The low-hanging fruit amenable to this type of discovery has been plucked years ago.
Yes. It was how I wouldve tried to claim these vulnabilities if I was a black hat. CompSci teams behind tools like Saturn often test them on FOSS code, both known-buggy and patched. The score is how many known bugs they catch vs false alarms. However, they often find new bugs with new tools even in well-trodden code.
Static analysis will not stop most of the exploits that have happened on iOS/OSX in the recent years.
Often it is a situation where multiple processes are working together and there is a way to trick a privileged process into modifying memory in a way it shouldn't.