I am also still unclear as to how they can promise such security since apparently you have to use an app on your smartphone to send transactions.
Because the transaction is created and signed on the completely "offline" (airgapped) cobo wallet device itself... and you only use your smartphone to scan the QR code off the cobo's screen and then broadcast the transaction. Basically the same theory as an airgapped PC generating a QR Code that you scan with a digital camera and then use online PC to broadcast.
Given that the transaction is already signed, there is no way to actually modify it on the smartphone.
Supposedly, the Cobo has no "interfaces" (ie. no usb connections, wifi, bluetooth etc) to be able to hack it... However, it does have an sdcard slot for uploading firmware... sooooooo yeah.