Assuming you mean the user-visible Android permissions model, a big problem with it, compared to object-capabilities, is that you can't choose among different implementations of each permission. E.g. if an app wants permission to listen to the microphone, you can't substitute a fake microphone that is always silent, or a virtual microphone provided by another app. You can only give it "the" microphone.
The ability to substitute is critical to a good capability system, because it allows finer-grained control over what the app can or can't do. E.g. you could, say, implement a custom microphone that reads from the real microphone when you're out in public, but produces only silence when you're in your bedroom. Without the ability to substitute, we must rely on the OS designers to provide all possible options for us, and of course they don't care to implement many options.
(OTOH, if you were talking about Intents, they are pretty capability-ish, though not always used well. Or if you were talking about some of the system internals like Binder, yeah, there's a bunch of capability-ish stuff in there.)