- Send the content of your clipboard to the internet (OnePlus)
- Disabled SELinux on boot (Asus)
- Allowed any app to be uid 1000, and exploit known for years (Samsung)
- Ignore Linux policy and just picked security-looking patches. And got pwned repeatedly by simply looking at LTS patches. (Google)
As for madaidans-insecurities, they are extremely biased.
Just mentioning microg:
> which allows apps to request to bypass signature verification.
There is EXACTLY *one* app (k k k, two because of Play Store fake too) that bypasses signature verification, and you can VERIFY, which app does it, and WHICH signature it fakes. LineageOS integrated their own microg/fake signature mechanism thanks to Google anti-freedom policy, and you can review their own integration that is even more restricted than what I did (which already is infinitely more secure than what madaidans-insecurities mention): https://review.lineageos.org/c/LineageOS/android_frameworks_...
The final comment in the microg section basically sounds like "oh yeah, that argument could be completely wrong, meh"