You either relax those restrictions in some way, or you can't run your code in the JS context of the page.
It's possible to run code in a content script regardless of how restrictive the pages's CSP headers are, but you are running in an isolated environment that can only access the page DOM.
For a Chrome extension using manifest v3: you can inject script tags with a src pointing to a local JS file in the extension regardless of the CSP.
Modifying the CSP is not a requirement for a Chrome extension to interact with a page's JS. I don't know about other browsers though.
In order to inject my code before theirs, I had to come up with different approaches on FF and Chrome... and since it was starting to become a cat and mouse game, I just took the extension private.
After that, they didn't escalate their game. I'm thankful for that, so that I can keep enjoying it without spending lots of time figuring out how to mess with it.