Problem is of course, Jailbroken Apple devices have EXACTLY the same attack vector. Windows devices have had that same attack vector (without needing to root, or change anything).

If you are jailbroken (which in the Apple world, is essentially the same as ticking the "allow installation of apps from untrusted sources" checkbox on Android), then guess what? Yep, a webpage can show a system dialog (as Safari also uses system dialogs in the browser), that makes it look like you need to download a file to install. If you install that file, you have become infected.

