Since Android has strict whole system SELinux MAC/MLS policies, there are only a few core processes (init, ueventd, vold) with something resembling actual root access in a production (user) build. Even init, etc. are still somewhat contained after init loads the SELinux policy.