This isn’t a bug “in android” since it can only happen when the user enables permissions to install third party app stores - the Fortnite installer is essentially an App Store that could be tricked to installing any APK rather than the one it means to.
The "bug" is that it is extremely difficult for users to install 3rd party apps securely.
If it was easier for developers to securely offer 3rd party downloads, then stuff like this wouldn't happen.
So i would argue this is not as simple as that.
I dont necessarily trust fortnite keeping their keys secure, for example.
Example here: https://f-droid.monerujo.io/
The only difficult part is the user getting f-droid on their device to begin with. If google play implemented the functionality provided by F-droid, they wouldn't need to.
Manufacturers should just put F-droid on new devices as standard.
There is a huge difference between no one has vetted this program and someone other than the device manufacturer has vetted this program. In a contest of "trustworthy not to contain malware" the Debian package manager beats Google Play, and you don't need approval from Dell or Microsoft to use it.