

Most of the chips in a smartphone are made by Qualcomm, both processors and peripheral chips like 5G modem, LTE modem, WiFi, and Bluetooth. Qualcomm chips require proprietary binary blobs to function, and usually only have a support lifetime of about 2 years. They also only supply those blobs to the manufacturer of the device.

SELinux is used on all the Fedora Immutable distros, and the OpenSUSE Immutable distro. It’s actually much easier to do SELinux in Immutable distros in a lot of ways than non-immutable. Especially the bootc-style ones where even more of the system is defined and prebuilt before deployment.
AppArmor is OK, but the whole issue is that you have to know what to throw into it. That’s also its benefit, you can focus in the high risk things and ignore the low risk things. It keeps expanding profiles more and more though, and ironically the ultimate destination is everything being under MAC.