I could see an object-capability based scheme working well.
Apple is probably in the unique position to actually implement such a system successfully, controlling the hardware, os, and even language choice.
Apple is probably in the unique position to actually implement such a system successfully, controlling the hardware, os, and even language choice.
Or they could continue with the current sandboxing system where security- and privacy-critical functionality is performed out of process, and plug the remaining leaks, of which there aren't that many.