Better hope that the factory manufacturing this device, and the technicians installing it within the phone, are trustworthy enough not to leave their own backdoors.
A supposedly trusted device that taps into the hardware buses by design is an excellent target for malfeasance.
So we assume that an adversary has dropped some malware that can silently enable the radio, activate the microphone, encode the audio stream and transmit it in real-time - and they want to avoid detection by this case.
Well, all they need to do is modify the malware to record the audio to a file and transmit it when the radio is next switched on, perhaps interleaving it with normal radio activity.