Earlier quoted context omitted.
In what way can PWAs be abused?
Sorry, I'm using the OPs parlance here – by PWA I think he means "JS apps that use advanced browser APIs". The typical concern is that a phisher will use to make a page that looks like Google's sign-in page and display it in fullscreen mode. This would let them collect credentials while mirroring the input in a real form that'd be filled in the background.
The new iOS 15 safari is full screen (and you’ve always been able to add to home screen to make a website really fullscreen)…