Rendering on client means you can still do all sorts of crap in terms of wallhacks, spoofing inputs and so on.
The solution for this that's now in vogue is server-side occlusion checking. Basically, map what objects/characters that player has line-of-sight on server-side, and send the client only data for those which are visible.
Could you do effective autoaim with just a rendered frame fast enough? I bet somebody would try.
This exists - it's usually done with a microcontroller that intercepts the monitor feed, scans nearby the player's cursor or center-of-screen for probable targets, and softly fuzzes mouse movements towards that target.
Hell, in some cases the cheating isn’t even on software these days. CS had a big argument about some keyboard behaviors recently, as did fighting games about leverless sticks enabling certain shortcuts.
Yep, 100%. That's why root-level AC is a bad option: cheaters are just switching over to these out-of-band techniques.
Companies prefer root-level AC because it gives non-technical stakeholders the impression that a game is "cheat-proof", and therefore, that they don't need to fund customer support to monitor and review reports of cheating. They're not using root-level, client-side AC because it's more effective than alternative options.