It's difficult enough to secure the supply chain towards the OEM as it is. It's nigh impossible for a vendor/OEM to secure the supply chain towards retail and distribution, not relative to nation-state attackers of great sophistication and with huge budgets. This sort of thing could happen with any smartphone, any feature phone, laptops, etc. Though it was a lot easier to mount this attack given an order for thousands of units from one company.
A man in the middle redirecting to a fake web page could be enough to create an opportunity. I assume that in some countries hacking the internet could be still possible.
Or a terrorist could sell phones on the street for months, use them as sleeping devices, and wait until a big holiday or the super-bowl to spread chaos massively with minimum risk for him/her. So now we everybody need a way to be able to scan our devices and detect that risk ASAP. The Mossad still don't understand the mess that had created for every westerner by opening this door.