With the permission system, you pretty much have to grant the app those permissions for it to do any harm. If you pay attention to what you install, and check the permissions requested before you proceed, you should be OK. Now, if you get apps from the darknet and install them without even checking what permissions they are asking for, you know what you're getting into.
Apps can always exploit vulnerabilities, but most threats can easily be prevented by just some common sense.
|