That's an unfair comparison. Any piece of software could try and 0day you. The point is that in a permission-based system, the permissions for browser extensions are in practice far too permissive to the point of being broken.
>You can't blindly trust anything "from the wild" yet you can't really live without it.
The point about permissions is to provide granularity to trust. I may trust an app to use my camera without trusting it to track my location in the background.
>Every app can abuse its permissions and track you/upload your photos/eavesdrop on your conversations.
This is the best comparison - mobile phone permissions - and on this front browser extensions are far worse. The majority of every single extension I install wants complete control to everything. In contrast, most apps only require a few things as appropriate. Yes, there are those flashlight apps which require _every_ permission, and those are basically the standard of extensions.
It should be added that UXSS (basically a malicious extension) is basically an RCE in the browser which in some cases is more beneficial than a full RCE, e.g. easier to steal banking creds.