Running something in the kernel is unavoidable if you want to actually show stuff to the user.
Attacker sends an imessage containing a PDF
imessage, like most modern messaging apps, displays a preview - which means running the PDF loader.
The PDF loader has support for the obsolete-but-part-of-the-pdf-standard image codec 'JBIG2'
Apple's JBIG2 codec has an exploitable bug, giving the attacker remote code execution on the device.
This exploit was purchased by NSO, who sold it to a bunch of middle eastern dictatorships who promptly used it on journalists.
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
* https://googleprojectzero.blogspot.com/2022/03/forcedentry-s...
PS: make sure you remove that pesky "USB accessories while locked allowed" profile that Configurator likes to sneak in.