How's it abusing anything? It's an Android app that works fine with the default Android memory allocator.
That doesn't necessarily mean it isn't being abusive, just that said allocator tolerates it okay.
The AOSP memory allocator is seldom the one used by OEMs.
Really? They're not using Scudo? The hardened_malloc used in GrapheneOS has a bunch of performance issues that were trade-offs against security. Every other major android distribution uses scudo as far as I know. Which OEMs are you thinking of?
Edit: Did some research after writing this? It appears that Samsung may be still using jemalloc, albeit a newer version than the one from the Android 11 days.
No, it does not have "a bunch of performance issues". It has carefully considered performance vs. security compromises which are largely configurable. GrapheneOS uses hardened_malloc in a very security-oriented configuration and has the option to disable it per-app if there's ever a compatibility or performance issue. GrapheneOS could also offer another toggle for setting it to a performance mode where it isn't significantly slower than Scudo either via dynamic configuration or a 2nd build of hardened_malloc with a lighter configuration. Most overhead is from slab allocation quarantines which are optional.
Yikes, didn't mean to trigger any defensiveness. Can't edit my comment, but mentally replace "bunch of performance issues" with what you said: "performance vs. security compromises".