Zero-touch OTA exploiting a cellular baseband processor in a phone is 100% possible if you control the network (which governments absolutely do). From there, it's just a matter of pivoting over to the application processor in order to enable the camera and mic. This path will almost certainly be less hardened than a userland to kernel privesc since the application-to-baseband interface will already be considered a trusted channel by the OS.
They don't have to install the backdoor themselves since that is clearly beyond the French police's reach. But if backdoors are already there they (France) only have to get access.
I doubt it, they can install any software they want on most people's phones. Sure in the future they can add supplemental hardware but it is very possible to do this measure currently on existing phones, unless you've rooted yours and install an alternative OS