How could you verify that these phones run the same setup as regular phones?
The only way to make companies fix bugs which may be difficult to find, expensive to fix, and potentially embarrassing is to make it easy to locate exploits on real hardware. Otherwise the only people with the resources to do this are government-backed entities like NSO Group, Vupen, etc, who somehow always ensure that exploits get into the hands of repressive governments.
Possibly compromising security for everybody just so 0.05% of the users can be happy is not a realistic expectation.