Respectfully, I think you’re drawing an incorrect inference.
They don’t exhaustively list all risks and perils, but that risk was known to me personally and documented by Apple at least circa 2020 — I worked with some third party developers to provide options to keep potentially high risk data out of APNS messages. Similar risks exist for Google’s platform. I’m not some genius with access to arcane knowledge, but if you’re doing your job it’s part of your risk assessment.
Judging by your very technical closing comment, this has no weight on your opinion, but I appreciate your taking time away from auditing Veracrypt or LUKS to read this.