I don't think so. The phones connect to a honeypot network and send over their credentials. The person who controls the honeypot now has their gmail password and so can use it to login and change their password.
I doubt your implication that they've broken the TLS layer just by having a honeypot. It sounds like they are taking advantage of exploits to own the phone itself based on their power on/off ability and may be stealing credentials straight out of memory. Or they are putting up a fake gmail honeypot as well and grabbing the passwords from there, but this seems less likely since most people use apps on their phones. Worst-case they actually do have a Google certificate and have in fact broken Google's TLS.
Gmail credentials are supposed to be delivered over an encrypted connection. Controlling the network should be insufficient to see passwords in transit. That said, passwords are a poor form of authentication that is prone to interception by poorly configured clients, HTTP downgrade attacks, and typosquatting login forms. I wouldn't jump straight to "0day".
If you're using a browser without certificate pinning wouldn't a MITM attack suffice? E.g. sslstrip