I know this could be any package but it feels like a yet another case against using random gimmicky forks of browsers that instead of "privacy" actually hurt the user

RE:
https://fosstodon.org/users/archlinux/statuses/114875363215235154
@natty I think it's another case against running software from unknown/untrusted sources in general. I'm even wondering how secure software from Flathub is, since I doubt people will audit a random unofficial wrapper package. See also the various version of Discord client there...