I've been watching platforms pull this move for twenty years. A real security problem shows up. The fix that ships is wildly disproportionate to the problem, and the collateral damage just happens to land on the things that gave users autonomy. Every single time, the individual decision has a defensible rationale. Every single time, the cumulative effect is platform closure.
Zoom out a little. Google's developer verification requirement for all Android apps lands in September. F-Droid's "Keep Android Open" campaign flagged this trajectory back in February. If both changes ship, Android loses sideloading of unverified apps AND rootless privilege escalation in the same quarter. The gap between Android and iOS for power users all but disappears.
Google does have a real problem. The PromptSpy malware discovery showed Android malware using Gemini AI at runtime. On-device capabilities are being exploited. Nobody serious disputes the CVE needs a patch.
But you can patch a wireless authentication bypass without killing local loopback. A scoped fix exists. Developer-mode exceptions exist. The fact that the proposal went straight to "nuke loopback entirely" tells you something about priorities.
The community thread is 800+ comments deep and climbing. Watch whether Google offers a scoped alternative. If this ships as proposed, expect GrapheneOS and custom ROM conversations to get very loud. September's verification deadline is the next shoe to drop.

