Some of the auto updated apps have a history of adding circumventable embedded browsers in about boxes and things on Android which can be used to browse the internet. This happens on iOS too but the browser engine is safari and is subject to the same white lists as normal Safari.
This is a fairly large security concern if I'm honest generally.
What's missing on Android that Apple has for control?