Earlier quoted context omitted.
That is and for many, always an issue. Adverts help pay for content, be that a game or website - people literally make a living that way that it has become a bit of a defacto approach. But when you are tied to including some code that goes off to a site that you have no or very little control over, you are outsourcing part of your company (web or app) into the hands of another in which, if they mess up. You are the t…
Here it sounds like the malicious code was in the advertising SDK itself, so ad blocking at the network level wouldn't necessarily have helped.
Maybe, Google et all need to make sure APP's have an even more granular control of permissions in that you can seperate the APP from the 3rd party AD's. that would only help more, but alas I suspect that may never happen as that would enable AD control much more accessible at a level that goes against their revenue stream.