This already exists. Apple processes can bypass app-specific filters (NEFilterDataProvider), but not system-wide firewalls (like the built-in BPF), VPN configurations, etc.
I’m marking this to remind myself to update my research. If anyone has references they are appreciated.
I thought they DID bypass vpn connections.
Also, apple will routinely clear your pf rules when installing stuff.
No, they only avoid being filtered by per-process filters. They can't bypass packet filters, by design; system-wide VPN connections work the same way, and cannot be bypassed.