This is way over my head but seems very problematic.
1) Fancy app website uses iframes to send messages to itself/its server
2) attack website embeds app in an iframe
3) attack website changes the URLs of the apps iframes to point to attacker-controlled pages
4) app sends sensitive info to its iframes, which of course ends up going to the attacker