Congratulations on your "common sense", but several highly publicized and actively exploited recent exploits against iOS required no user interaction:
https://arstechnica.com/gadgets/2020/12/iphone-zero-click-wi...
https://arstechnica.com/information-technology/2020/12/zero-...
https://arstechnica.com/gadgets/2021/07/clickless-exploits-f...
etc., etc.