I'm sure I'm missing something, but given how many there have been wouldn't you at least stick an `assert(!isPhoneLocked())` or similar on entry to anything that shouldn't be accessible while locked?
The bugs seem to a bit more nuanced than just testing for a locked device; the attacks seem to rely on performing actions simultaneously to exploit race conditions much like weird glitches in games. This class of bugs is really hard to test for due to the large search space. Model checking might offer a solution, but it's not a magic bullet by any means.