Yup. That's every app's problem though. I can also create a webpage and design a fake "bank login" inside of it to make you enter your credentials there. There is nothing you can do about that other than educating the user.
Yes, but browsers design goal is to allow educated users to distinguish fake and legitimate sites (URL bar should never be forgeable). With mobile apps, the app can display anything and there is no way for even well educated user to recognize forgeries.
The aim is therefore to remove the reliance on it being genuine. If you don't have passwords then there is no passwords to steal.
I think that's Android/iOS responsability.
The OS can't know the intent of the view for certain, so no.