Signal should separate WebRTC handling into its own process so that an exploit doesn’t have access to its critical database.
A messaging app has almost all the same security concerns as a browser, so the recommendations here apply: https://developer.apple.com/documentation/browserenginekit