And an often under appreciated tenet of security — even a “good” software can be exposed to “bad” data, and you only need a bug (especially a memory bug, which is exceedingly common because linux userspace can’t get rid of c for the life of it) to have arbitrary code executed.
Like, your pdf reader is surely not evil, but do you trust every single pdf file you open?