vulnerability
My understanding is this has less to do with Signal than phones themselves. Signal messages are decrypted and stored on the phone itself, so a successful attack on the phone would allow access to the messages.
This is completely fine for personal use since the average person isn't going to be a target, but for classified information, that's unacceptable. This isn't unique to any messenger, any app that stores data on the phone is open to it.