> E2EE is actually a boon to NSO and friends.
I think you're right, but I don't think it's due to some first principles contradiction between E2EE and exploits as much as it is largely a historical anomaly that customers have looked to service providers for security. The track record shows pretty clearly that the service provider's interest in customer security only goes as far as not to be reputationally damaging - we've seen plenty of communications companies actively helping authorities to spy on their own customers.
> If iMessage weren't E2EE it would be very easy for Apple to implement a heuristic to look for suspicious messages
Indeed, it would at the very least be easier, but let's assume Apple did have this capability. The first order of priority would be stopping spam, which is orders of magnitude more common and problematic than targeted exploits. Simply taking a look at the app store kind of shows their ambition level. At best, Apple is going to want to be "more secure than Android", but beyond that.. it's simply not gonna be a priority (and Apple is even one of better ones).
> NSO sometimes goes on years exploiting the same iOS bugs before Apple figures them out
Yes, but I think this is temporary. Citizen Labs have been shortening this round trip time enormously simply by having analysis or software deployed on likely targets' devices. CrowdStrike and similar security companies operate on a similar model, acting as a counter-surveillance trusted third party. On medium-term time scales, I think such models are more ethical, have a superior incentive structure and, most importantly, will prove to be more effective than the usual half-assed service provider solutions. At least, I hope I'm right.