No.
In a way it does not matter if the app is system or not. Even user apps (signed with some other key) can be powerful to do damage.
System partitions cannot be edited due to SELinux and also thesedays the partition ext4 is created with certain blocks - cant be changed.
Yes one can use magisk to do some gimmick - but that is kinda telling OS - Allow me to do anything.
The notion of locked bootloader as a holy grail against anything is stupidity. Apps inherently have too much power - assuming user somehow granted permissions. (or you are from a 3-letter organisation - incl. NSO)