Have you never seen a native app's auto-update get hijacked by malware? It happened (yet again) last month [0]
Tons of native apps also have plugins or addons, which (surprise surprise) is just code downloaded from some central repo, and run with way less sandboxing than JS.