I suspect you're arguing from the point of view of a determined attacker against a specific target, in which case, I agree -- there's an infinite number of different attacks you can try, with the caveat that any failed attempt is possibly going to tip your target off and make them up their opsec game, becoming a much more difficult target.
I took the OP to be talking more about general case. Random people plugging into a public recharge station, using (shady) Amazon/Ebay USB drives, plugging in a "found" USB stick, etc. The OS can at least help thwart simple attacks here.
In the worst case, the device contains a GSM modem which is powered by USB but otherwise only appears to the host as a USB drive -- and if you can get the target to write useful data to it, I guess you have something? That's an awfully expensive attack that I would assume has relatively low chance of yielding something useful. (Unless maybe you market it as a "secure cryptocurrency wallet", and hope you can sell enough to people that then put on enough cryptocurrency to make up for the significant manufacturing expensive which you're able to steal before anyone notices there's a modem in it and sounds the alarm..)
> You could do similar things with a USB stick. You could have a high voltage converter which fries your PC the second you plug it in.
This has not only been done, it is a commercial product: https://usbkill.com/
While being obnoxious and causing one (random?) person some money (presumably they will destroy or throw out this USB drive aftward), it doesn't really get you anything. There's many other cheaper ways to destroy someone's computer, as there are many other things you can destroy to cause a person expense and/or inconvenience.
> Basically, it is always a bad idea to plug in unknown peripherals to your computers. The OS isn't going to save you in all cases.
100% agree, but that doesn't mean it shouldn't try at all.