Android no longer reveals app permission changes in automatic updates
arstechnica.com
arstechnica.com
The damaging code could be obfuscated and compiled into a binary module. In order to prevent Google (or Apple) from shutting down updates before it reaches too many people, the malware payload could trigger at a certain time or based on a network command once the update is installed everywhere.
Imagine someone flooding Verizon's network with traffic at a coordinated time and bringing the network down. Or rending a large percentage of iOS products inoperable during a WWDC keynote. There would be a lot of money to be made by shorting the stock of the affected companies.