Just like any other wallet.
Each wallet had vulnerabilities in the past. There is not a single one which didn't.
And some do even still have vulnerabilities which will never be fixed (e.g. jaxx).
Even if you know the sender you shouldn't click on links without verifying it.
If the original sender is compromised, malware could send emails to all contacts. While you'd believe the sender is a well known friend, in reality it is just some attacker who compromised the system of your friend.
Do not trust, verify.