Why are there more likely to be holes in that IPC than the SYSTEM one?
Why are those holes more dangerous than having the entire thing happen in SYSTEM land?
Naturally, there's a danger that it's not bullet-proof and will lead to escalations/escapes. However, how is the risk of that not a strict improvement over the situation where it's running as SYSTEM and doesn't even need to bother with that?
It sounds like it's strictly harder to weaponize faults in the component if they need to find a secondary problem in IPC encapsulation over just running code as SYSTEM as soon as they compromise the component.