Sure, attackers could connect something mimic a whitelisted USB vendor+product ID, but in that case the drivers/co-installers are probably already present anyway, and it still greatly reduces the attack-surface since they need to find an exploit in those particular products.