They would have to do it for all commercially-available devices. Why would they pick the one device you have to compromise and leave out all the others. You'd need a special government department with maybe a hundred employees taking every device coming out commercially and figuring out durable, undetectable compromises, where it's not even a given that it's really possible to do so on them.
If you're insinuating they do this already, then don't you think that would have been the very first bomb dropped by Snowden? Snowden had access to everything. You don't spin up a department like that overnight, it takes years before the department will work well enough to rely on in different situations.
Obviously they investigated it. But there's a big difference between exploring at how it could be done and actually producing and distributing real exploits that could be used by Joe Shmoe, federal agent.
If you're insinuating they do this already, then don't you think that would have been the very first bomb dropped by Snowden? Snowden had access to everything. You don't spin up a department like that overnight, it takes years before the department will work well enough to rely on in different situations.