Unless I'm mistaken (and I probably am, it is not my field), the attack vector is to get admin rights once (e.g. on install), and then build an identify that allows nefarious activities without asking again for admin rights. As everything asks for admin rights on install/update and everyone just clicks it (what else are you supposed to do?), admin rights are easily got at least once. As I say, YMMV...

