> I'd rather have restrictions as the default
Then don't install apps and use the web, mobile sandboxing is much weaker compared to any modern browser.
Wrong answer...
How so? The accessibility API which is causing data exfiltration here doesn't even exist on the web.