One of the most common is “scanning” your location constantly, feeding your daily routines to marketing data aggregators, which is arguably more invasive of the average person’s privacy than CSAM flagging.
I’ve posted in the past a list of a short-list of offending SDKs frequently phoning home from across multiple apps from multiple developers. Since weather apps sending your location surprised people, I thought this problem would get more traction.
This Apple thing, where this is iCloud file upload client SDK doing a thing on upload, is an instance of this class of problem.
It’s not an Apple thing, it’s a client SDK thing, and the problem of trusting actions on “your” end of a protocol or cloud service is not a solved thing.