Hacker News new | ask | show | jobs
by Etheryte 1225 days ago
This is not a threat model that's unique to PWAs though, nor in any way enabled by what's seen here. Installing a PWA is practically equivalent to installing an app and a malicious app or an app that had their OneSignal or similar credentials compromised could do the exact same thing.
1 comments

Apple can disable push notifications from a compromised app.

It's unclear if they can do it for a compromised website, which was my question above.