Software security can be thought of as operating on a cost/benefit model. To produce secure software means making attackers spend more resources on penetrating defences than the value they get from successful attack. And it works well for mass market, because the vast majority of attacks are non-targeted attempts to fish for financial credentials, taking over the devices for use in a botnet etc.
For state attacker the model breaks. The value of a target can be very high. And the available resources - financial, technical, other - are there to fill the budget.