Author of the above blogpost here.
To my knowledge the situation has changed nowadays and IOMMUs on smartphone SoCs are now common. Having said that I still don't rate the security of any smartphone and you should assume it will get compromised. There's a million reasons for this:
- Baseband is still radioactive and probably trivially compromised by any nation-state adversary so it's all down to the IOMMU.
- IOMMUs are hard to configure correctly and frequently misconfigured by drivers which don't use them correctly.
- Any host driver bugs in talking to the baseband might be exploitable.
- It's hard to verify an IOMMU is actually working correctly, so it's not like any of this is commonly audited.
- We're talking about SoCs here with the baseband usually integrated on the same chip, so there's always the risk of some undocumented channel between the baseband and the rest of the chip the vendor omitted to notice or tell anyone about.
The situation is at least better than it was but it's still 100% my assumption that no phone can be trusted in the face of an adversary who can put up a fake cellular network. There's simply far too much proprietary firmware, mysterious black boxes, etc. to be able to really trust these things.
Also I'm assuming here there's a desire to get access to the host processor and stored data, but you don't need to do that if you just want to get at the microphone or GPS or leak someone's location or so on. There's a million bad things someone could do getting access just to the baseband even if the IOMMU works right.