This gets into sandboxes needing to have "sacred pixels" as a border to prevent the sandbox tricking the user into thinking they exited from the browser
This issues goes way back: imagine if after executing a program on CLI instead of closing it gave you a fake shell, where you eventually went about your day until you had to type your password into sudo..
Of course, your point about the app store is good motivation to address this, whereas consoles don't go about offering much protection there
Is this even the case anymore? On Android, all my URL bars peel up into the top of the screen as I browse, and I'm pretty sure a website can capture the vertical swipe/arrange an inner-scrolling element to make it very difficult to quickly get the URL bar visible again.
I think that would be enough to trick most users. This seems like an unnecessary limitation
As a fun fact, even worse might be a program maliciously aliasing sudo in ~/.profile
But then again how, how someone know if that happened!
For background, there is a convenience feature in sudo: It only requires your password prompt if you have not had a successful sudo invocation in the same terminal in the last X minutes (5 minutes, I think? not sure on the exact value). "sudo -v" is a special invocation which does not actually execute any command, but it renews your 5-minute lease. ("sudo true" is effectively equivalent, though not idiomatic.)
So if you're executing a short script that needs sudo, run "sudo -v" before running the actual script. Then you know that if a root password prompt pops up again, it's not really sudo who's asking.
The bigger problem is that even without sudo or your root password, malicious scripts can do a lot of damage. ie. they can add a fake sudo to your .profile, so you next time you try to do "sudo -v" your password still gets stolen.
Every "security" feature on Safari points into harming web apps so you are on the right tracks...