Regarding #2, that bug was fixed a year ago to the day, according to the very source you linked. I feel it's unfair to include what was clearly a mistake in the same category as deliberate malicious activity (#1 and the linked article)
Agreed, one is incompetence (remember, the stock Android browser had to be specifically patched by Samsung to enable the feature) and the others are simply not caring that much about customers. I don't feel it's unfair though.