The carrier setting thing hasn't ever been use for a jailbreak exploit AFAIK so chances are it's not a good attack vector.
From your other comment:
> But it mentions the option of wiping baseband firmware
iOS also has signature verification for its baseband, since trying to load an incompatible one during a downgrade[0] breaks Face ID / Touch ID.
But ya, this is all "trust apple to not do anything". They've made a good stance with refusing the FBI request[1], but the FBI got into the phone anyways[2].
0: https://github.com/tihmstar/futurerestore
1: https://news.ycombinator.com/item?id=11116274
2: https://venturebeat.com/2016/03/28/u-s-government-gains-acce...