You got this flipped. The whole point of "fingerprinting" is to build a stable identifier that works even if a explicit identifier (IMEI or advertising ID) isn't available. And yes, there are shady SDKs that do this without facing repercussions.
https://www.buchodi.com/i-broke-applovins-mediation-cipher-p...
IIRC Apple also specifically prohibits exporting device signals like boot time and available disk space, so that SDK would be in violation of their rules if the description is accurate.
https://developer.apple.com/documentation/bundleresources/ap...
* https://www.cnbc.com/2022/02/02/facebook-says-apple-ios-priv...
See also perhaps "It’s not Meta - its APPLE who have screwed us small advertisers":
Do they really allow any app to be downloaded on mil phones?