Reminder: stuff is sandboxed now, and it also probably doesn't run as root. Also, busybox has been updated, no more tarbombs.
Because pretty much anyone can craft an actual update package (or the various other things that go through a simile of the OTA updater) that goes far enough to throw a U007, nothing fancy required there

.