Required review by Apple? That malicious code is restricted from doing much precisely by the sorts of things OP is complaining about? The potential economic return isn't as high because Apple can forcefully clean it off? That it's harder to be anonymous when $100/year has to change hands for a cert and Apple wants to know who you are on some level so it'd be at least somewhat harder to avoid them going after you? None of these are bulletproof, even combined. But even so they're not worthless either to that goal. Are you actually asserting that the actual state of malware on iOS is identical or worse then that of Android or Windows/Mac/Linux? That's not something I've seen supported before but I'd read a good source if you've got one.