Hacker News new | past | comments | ask | show | jobs | submit login

Android apps can anytime do remote code execution. GrapheneOS even offers controls to restrict Dynamic Code Loading per app. But Google somehow cares only about RCE in browser extensions?



Note: I am the author of this article.

Apples and oranges. Android is supposed to isolate apps from each other (yes, theory). So a malicious app should only be able to steal data the user provides it with.

On the other hand, a single malicious extension will compromise the entire browser. Nothing you do on any website is any longer safe.

Not that I don’t think that Google should pay more attention to the apps in the Play Store. But allowing extensions to hide their functionality with remote code is plain negligent.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: