"It’s impossible to be sure that cybercriminals will never get ahold of the browser developer’s servers or use the update feature to infect hundreds of millions of Android devices." Apparently they didn't consider the same sentence would be just as valid if they replaced "browser developer" with Google... This is an example of the authoritarian security sensationalism that's far too common today, and it only leads to…
> This unofficial update feature present in UC Browser can also be used by would-be attackers to perform man-in-the-middle attacks (MitM) attacks, potentially leading to remote code execution on compromised devices, because the app communicates with its servers using an unencrypted channel over HTTP.
It's a lot easier to use the update feature to infect millions of people when it's just using plain HTTP.