I believe the breaking of security features would come in when the researchers’ app attempts to monitor the use of public APIs and SDKs by other apps - i.e., breaking out of the sandbox to see what the other apps are up to.
I believe the breaking of security features would come in when the researchers’ app attempts to monitor the use of public APIs and SDKs by other apps - i.e., breaking out of the sandbox to see what the other apps are up to.