[flagged]
That said, the alternative to web apps is native platforms or other VMs which have the exact same problem except with less capital allocated towards mitigating it.
Not really, at least on desktops: https://microsoftedge.github.io/edgevr/posts/Super-Duper-Sec...
https://developer.mozilla.org/en-US/docs/Web/Security/Attack...
What stops malicious JavaScript that would have used moveBefore() to just add key event listeners?