The hardened_malloc project has performance vs. security configuration. It's used in a very security-oriented configuration in GrapheneOS. GrapheneOS could offer a performance vs. security toggle for this but hasn't yet included one since there are rarely apps with any noticeable performance difference. Android apps are mostly written in Java/Kotlin where it makes no difference. There are often specific uses of optimized C, C++ or Rust code where it makes little difference. It's rare for an app to be heavily impacted by malloc performance as if it's a malloc microbenchmark, and even in that case the overhead is typically quite reasonable. OsmAnd is doing something very strange in a certain configuration.