GNU/Linux phones (Librem 5 and Pinephone), but they aren't polished yet.
The primary cause of this problem is the conventional desktop OS which has no meaningful security model.
IOS and Android have the correct approach to mitigate this, strong sandboxing and mandatory access control.
GNU/Linux phones bring these problems to mobile, which considering how much of our lives are on these devices, is an absolute disaster.
The only way to meaningfully secure a GNU/Linux desktop is to run multiple instances of it through a type-1 hypervisor.
For a mobile device, a user prioritizing privacy, security and FOSS would be much better served by GrapheneOS.