eh, it's situational really, i have the policy of never letting my phone out of sight lol, and would automatically assume it to be compromised if that happened, which essentially makes boot integrity moot (it's a higher barrier to entry, but it's a choice someone can make)
plus, that's actually something really unique to android, desktop systems are similarly insecure in that regard (even secure boot doesn't *really* fix anything since it's trivial to disable by wiping the motherboard's memory, android's key benefit is that bootloader unlocking requires a storage wipe, which makes it obvious that tampering happened), so it's less that pmOS is particularly insecure and more that computers in general are quite insecure and android just happens to be exceptionally good in that aspect lol
and although pmOS doesn't have android-like sandboxing OOTB, it's not really impossible to implement it with bwrap/firejail, it's just a specialized use case
