But can apps sniff in what website or app you are using the password? Either for iOS or Android, if the password are just random strings unique for each site and they can't determine that then the attack vector diminishes.
Plus it really doesn't matter, because when it comes to security, there's also the issue of the mono-culture and user technical stupidity. We know that many people use Gmail, Facebook, Twitter, etc, most of them reusing passwords across services. And logging the user's copy/pasted texts gives you such a specific dictionary that the probability of getting hacked approaches 1 fast.