Conversation

Replying to
It's still possible to update privileged apps out-of-band and add new privileged permissions. The new privileged permissions just won't be granted until the OS is updated to a version with them included in the static whitelist.
1
2
Replying to and
An OS update was required to add a new priv-app before this feature was implemented. The difference is only that out-of-band updates to the priv-app cannot expand the permissions beyond the whitelisted set. The apps often come from a third party like a carrier.
1
2
Replying to and
One of the issues that this mitigates is the third party arbitrarily expanding their privileged permissions. They could release an update expanding it to the whole set of available privileged permissions on the device. It makes it so that they need permission from the OS first.
1
2