I don't think many experts would call iOS "easily exploitable", especially if you don't install random apps and browse the web. 0-days aren't easily available for places like Iran, Syria, Egypt, etc, or even larger countries like Brazil, and wouldn't be burnt on any ordinary suspect. They still usually rely on the user clicking a link. A locked down iPhone (no BT, WPA2-EAP, VPN, Signal, hard passphrase) is a hard target.
If your contact is the type who will record the fading Signal messages with another phone you're already fucked.
If your contact is the type who will record the fading Signal messages with another phone you're already fucked.