Closed Source:
- Team behind it could add trackers, backdoors, etc that are difficult to detect.
- Attackers could find an exploit that will go unnoticed and unfixed for an indeterminable length of time. Or perhaps use the team's own aforementioned exploits/backdoors.
- Can't tell if their app is well-tested and well-written, which means it could be a buggy hot mess from the get-go. Which is the most common reason for hiding source from my anecdotal experience.
Open Source:
- Much easier for anyone to find a bug, including attackers. You'd hope the maintainers/community will find the bug before them, or at least take less time to fix it than if it were closed-source.
- Attackers could add their own exploit that will go unnoticed or unfixed for an indeterminable length of time.
I think the conclusion to draw from is:
Closed Source = less likely for attackers to find bugs, but more likely for bugs to persist. Can only trust in the company's reputation for code quality.
Open Source = more likely for attackers to find bugs, but less likely for bugs to persist. Don't need to trust the company's reputation for code quality.