(If its easier for the question, we can assume a non-ancient version of Android - say Android 12 or newer)
I am aware that running an unlocked boot loader can allow hacked firmware to be run on the phone, but understand that Android - or at least some versions of android/some distributions - offer at least some warning/protections (i.e. a warning if the firmware is unsigned).
For various reasons (warranty related) I would like to purchase a phone with a boot loader that is unlocked. Assuming that either I flash known good firmware or that the installed firmware is signed is there any risk of the phone being compromised over and above the risks if I unlocked the boot loader myself?