Right, which is why I'm baffled as to why they'd introduce scanning in 2022
If you want to catch real zero-days, you have to approach things very differently. Do behavioral analytics, seeing what a process is up to and if it's poking into things it shouldn't.
Many leading AV suppliers like SentinelOne, Cylance, Crowdstrike do this and are very successful at it. However Apple is just starting in the antimalware market so I forgive them that they're just scanning for some known-bads for now.