Previously a company could issue Chromebooks to all employees and know that employees can't run arbitrary binaries on their Chromebooks.
Previously a company could issue Chromebooks to all employees and know that employees can't run arbitrary binaries on their Chromebooks.
Hmm...
Chrome Has a Malware Problem, and Google Needs to Fix It (https://www.tomsguide.com/us/chrome-extension-security-probl...)
Chrome Extension Malware Has Evolved (https://www.wired.com/story/chrome-extension-malware/)
How Malware Keeps Sneaking Past Google Play's Defenses (https://www.wired.com/story/google-play-store-malware/)
New Android Malware Infected 2 Million Google Play Store Users (https://thehackernews.com/2017/04/android-malware-playstore....)
There's definitely an increased attack surface inside the VM, but that's kind of unavoidable if you want to have a development environment (what this is marketed for). At least Chrome OS offers a secure way to isolate your development environment from your email/banking/etc processes.
Such a step was already necessary to disable Android apps.