You're trivializing how difficult tampering with OS internals in locked down secure boot environments can be. Just look at the state of Android custom roms. Devices that are years old can be impossible to modify the OS on.
Look at projects like byeDPI. Essentially, it's just a VPN service that runs on the phone itself.
You phone connection is passed to this VPN that modifies http-headers.
I kinda did forgot about Android, yeah. You can't exactly rewrite OS rules there. But it's no less trivial* on Android, you just have to solve it from different angle.
* assuming someone will just write the app, and share it. But since similar projects exist, it wouldn't be a reach to say that it's doable and some folks would be interested to do it.
Look at projects like byeDPI. Essentially, it's just a VPN service that runs on the phone itself. You phone connection is passed to this VPN that modifies http-headers.
I kinda did forgot about Android, yeah. You can't exactly rewrite OS rules there. But it's no less trivial* on Android, you just have to solve it from different angle.
* assuming someone will just write the app, and share it. But since similar projects exist, it wouldn't be a reach to say that it's doable and some folks would be interested to do it.