In that case, both FDroid and the browser are intermediaries and potential attack vectors. You go through the same number of middlemen. One just verifies the packages for you.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: