Mlem in app browser is using an in app browser API that is secure by design. It doesn’t allow snooping or injecting anything. This article is talking about abusive apps like Facebook that roll their own in app browser.
Edit: although on iOS, the secure iOS in app browser api is always using safari engine, so the user choice argument is still valid.
Now do jxl support