What about turn JS off on your favourite iOS browser?
However I also expect that Swift-compiled apps can do this without a web browser component.
It’s a different threat model though, having installed a malicious app vs browsing a malicious site.
Having said that there are apps that are considered mainstream and not malicious by the general population but can become a convenient backdoor for, say, a state actor.