Android has demonstrated that you can have multiple app stores and that majority of users will happily use the default app store which for vast majority of Android phones is Google Play store.
Malware has made it into Google Play store which is Google's fault.
Same has happened to Apple (https://9to5mac.com/2021/05/07/emails-reveal-128-million-ios... https://us.norton.com/internetsecurity-emerging-threats-ios-...) so you cannot be guaranteed to be safe just because you are behind a walled garden, you still need to think for yourself.
Allowing app side-loading or different app store is not a security hole.
Using non-approved apps or non-trusted app stores might allow for existing security hole to be exploited more easily but it might also allow for better protection against such security hole by providing better curated app stores for less tech-savvy users.